This is core component of Kata Container, to make it work, you need a isulad/docker engine.
Security Fix(es):
'This vulnerability was fixed in Kata Containers 3.31.0:', 'Description:\n\nIn the runtime-rs standalone virtio-fs path, Kata Containers runs virtiofsd\nas root with --sandbox none --seccomp none.\n\nIf an attacker has root-equivalent execution inside the Kata guest VM,\nthey can send raw FUSE requests directly to the host virtiofsd.\n\nThen, a raw FUSE_SYMLINK request whose new symlink name is\nan absolute host path is honored outside the virtio-fs shared directory.\n\nThis lets guest root create host-root-owned symlinks in sensitive host paths.\n\nCVE: CVE-2026-47243\nGHSA: GHSA-2gv2-cffp-j227\n\nOriginal report:', '---\nAurelien Bombo\nKata Containers Vulnerability Management Team'
{ "severity": "High" }
{ "src": [ "kata-containers-3.2.0-22.oe2403sp3.src.rpm" ], "x86_64": [ "kata-containers-3.2.0-22.oe2403sp3.x86_64.rpm" ], "aarch64": [ "kata-containers-3.2.0-22.oe2403sp3.aarch64.rpm" ] }
"https://repo.openeuler.org/security/data/osv/OESA-2026-2557.json"