Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFil…
High CVSS 8.2
Summary
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/kata-containers/kata-containers/commit/1b9e49eb2763aa6ea6a99b276d3ff5e2c7f658f2 Patch
- https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/05/13/2 Mailing List
- https://access.redhat.com/errata/RHSA-2026:25200
- https://access.redhat.com/security/cve/CVE-2026-41326
- https://bugzilla.redhat.com/show_bug.cgi?id=2460859
- https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41326.json
Timeline
- nvd_ingest NVD