Junglewise Threat Intelligence

CVE-2026-44210: Kata Containers VM escape via virtiofsd argument injection

CVE-2026-44210 · Severity: medium · CVSS 4 · Published 2026-07-23

Technologies: github.com/kata-containers/kata-containers (Go). Vendors: Go.

Executive brief

Kata Containers, a tool used to run lightweight virtual machines that act like containers, contains a vulnerability in its default configuration. An attacker with the ability to create pods (containers) can bypass security boundaries to access the underlying host server's entire file system. This allows the attacker to read or modify sensitive files on the host, such as passwords and system configurations, potentially leading to a full takeover of the server and other containers running on it.

Technical details

Kata Containers versions prior to 3.31.0 are vulnerable to an argument injection flaw (CWE-88) in the virtiofsd process. The default configuration enables the `virtio_fs_extra_args` and `kernel_params` pod annotations without sufficient validation of their values. An attacker with pod creation privileges can use the `virtio_fs_extra_args` annotation to inject `-o source=/`, overriding the shared directory to the host root. When combined with the `kernel_params` annotation to enable the agent debug console, the attacker can mount the host filesystem from within the guest VM. This results in a complete VM escape, allowing unauthorized read/write access to the host's files, including `/etc/shadow`. The issue is resolved in version 3.31.0 by disabling these annotations by default.

Affected products

  • Kata Containers Kata Containers < 3.31.0

Timeline

  • 2026-05-20: advisory: GitHub Security Advisory GHSA-rr59-xxvx-96qr published
  • 2026-07-23: disclosed: CVE-2026-44210 published to NVD
  • 2026-07-23: patched: Version 3.31.0 released with fix

References

Related threats