CVE-2026-44210

Source
https://cve.org/CVERecord?id=CVE-2026-44210
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44210.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44210
Aliases
Published
2026-07-23T17:32:23.927Z
Modified
2026-07-24T04:02:28.886604460Z
Severity
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:P CVSS Calculator
Summary
Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
Details

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the io.katacontainers.config.hypervisor.virtio_fs_extra_args pod annotation. By injecting -o source=/ along with --no-announce-submounts and --sandbox=none, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the kernel_params annotation (also enabled by default) to activate the agent debug console, the attacker can mount the host filesystem from inside the VM and read or write any file on the host, including /etc/shadow. Version 3.31.0 patches the issue.

Database specific
{
    "cwe_ids": [
        "CWE-88"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44210.json"
}
References

Affected packages

Git / github.com/kata-containers/kata-containers

Affected ranges

Type
GIT
Repo
https://github.com/kata-containers/kata-containers
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.31.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.10.0-rc0
1.11.0-alpha0
1.11.0-alpha1
1.9.3
2.*
2.0.0-alpha1
2.0.0-alpha2
2.0.0-alpha3
2.0.0-rc0
2.1-alpha0
2.1-alpha1
2.1.0-alpha0
2.1.0-alpha1
2.1.0-alpha2
2.1.0-rc0
2.2.0-alpha0
2.2.0-alpha1
2.2.0-rc0
2.3.0-alpha0
2.3.0-alpha1
2.3.0-alpha2
2.3.0-rc0
2.4.0-alpha0
2.4.0-alpha1
2.4.0-alpha2
2.4.0-rc0
2.5.0-alpha0
2.5.0-alpha1
2.5.0-alpha2
2.5.0-rc0
3.*
3.0.0-alpha0
3.0.0-alpha1
3.0.0-rc0
3.1.0-alpha0
3.1.0-alpha1
3.1.0-rc0
3.10.0
3.10.1
3.11.0
3.12.0
3.13.0
3.14.0
3.15.0
3.16.0
3.17.0
3.18.0
3.19.0
3.19.1
3.2.0-alpha0
3.2.0-alpha1
3.2.0-alpha2
3.2.0-alpha3
3.2.0-alpha4
3.2.0-rc0
3.20.0
3.21.0
3.22.0
3.23.0
3.24.0
3.25.0
3.26.0
3.27.0
3.28.0
3.29.0
3.3.0
3.3.0-alpha0
3.3.0-test
3.30.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.9.0
Other
untagged-b5b6198308b02e3a2666
untagged-c2a61792b39392572d0f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44210.json"