Bug 2500228 (CVE-2026-50540) - CVE-2026-50540 kata-runtime: kata-runtime-rs: Kata Containers: Arbitrary code execution via manipulated configuration path
Summary: CVE-2026-50540 kata-runtime: kata-runtime-rs: Kata Containers: Arbitrary code...
Keywords:
Status: NEW
Alias: CVE-2026-50540
Deadline: 2026-07-20
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 18:09 UTC by OSIDB Bzimport
Modified: 2026-07-22 17:08 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-14 18:09:27 UTC
A vulnerability has been reported in the Kata Containers configuration loading path in both the Rust and Go runtimes. Both runtimes accept the sandbox configuration file path from the pod annotation io.katacontainers.config_path. This path is then passed to the TOML configuration loader without sufficient validation or restriction. An authenticated pod user who is able to set pod annotations may point io.katacontainers.config_path at an arbitrary TOML configuration file available on the host. Since the Kata configuration controls privileged runtime settings, including hypervisor and virtio-fs daemon binary paths, a malicious configuration may cause attacker-controlled binaries to be executed as root on the host when the sandbox starts.


Note You need to log in before you can comment on or make changes to this bug.