Guest-Root to Host-Root Escape in Kata Containers by Kata Containers
CVE-2026-47243
9.2CRITICAL
What is CVE-2026-47243?
The Kata Containers project is vulnerable due to its handling of the virtio-fs path prior to version 3.31.0. An attacker with root-equivalent access within the guest can exploit this by taking control of the virtio-fs PCI device, which allows them to communicate directly with the host virtiofsd process. This manipulation lets them execute a crafted FUSE_SYMLINK request that can create symlinks in sensitive locations on the host, such as /etc/cron.d. Consequently, this could enable the attacker to run their payload with host root privileges, effectively violating the isolation intended by Kata Containers. This vulnerability was addressed in version 3.31.0.
Affected Version(s)
kata-containers < 3.31.0
