Vulnerability in Kata Containers Affects Lightweight Virtual Machines by Kata Containers
CVE-2025-58354
6.9MEDIUM
What is CVE-2025-58354?
In certain versions of Kata Containers, a vulnerability exists that enables a malicious host to bypass initdata verification processes. This flaw can be exploited on TDX systems running confidential guests, allowing an attacker to deliberately cause IO operation failures. As a result, attackers can launch unauthorized workloads while masquerading as legitimate processes. This vulnerability emphasizes the need for users to upgrade to Kata Containers version 3.21.0 or later, where the issue has been addressed.
Affected Version(s)
kata-containers < 3.21.0