Bug 1848294 (CVE-2020-2026)

Summary: CVE-2020-2026 kata-containers: Possibility to mount untrusted container filesystem on any host path leads to Remote Code Execution
Product: [Other] Security Response Reporter: Marian Rehak <mrehak>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: crobinso, dinechin, jose.carlos.venegas.munoz, lsm5
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-28 05:26:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1848295, 1848296, 1848297, 1848298, 1848300, 1848301    
Bug Blocks:    

Description Marian Rehak 2020-06-18 07:49:26 UTC
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.

Upstream Issue:

https://github.com/kata-containers/runtime/issues/2712

Comment 1 Marian Rehak 2020-06-18 07:50:17 UTC
Created kata-agent tracking bugs for this issue:

Affects: fedora-31 [bug 1848295]


Created kata-ksm-throttler tracking bugs for this issue:

Affects: fedora-31 [bug 1848296]


Created kata-osbuilder tracking bugs for this issue:

Affects: fedora-31 [bug 1848297]


Created kata-proxy tracking bugs for this issue:

Affects: fedora-31 [bug 1848298]


Created kata-runtime tracking bugs for this issue:

Affects: fedora-31 [bug 1848300]


Created kata-shim tracking bugs for this issue:

Affects: fedora-31 [bug 1848301]