Guest-Root to Host-Root Escape in Kata Containers by Kata Containers
CVE-2026-47243

9.2CRITICAL

Key Information:

Vendor
CVE Published:
7 August 2026

What is CVE-2026-47243?

The Kata Containers project is vulnerable due to its handling of the virtio-fs path prior to version 3.31.0. An attacker with root-equivalent access within the guest can exploit this by taking control of the virtio-fs PCI device, which allows them to communicate directly with the host virtiofsd process. This manipulation lets them execute a crafted FUSE_SYMLINK request that can create symlinks in sensitive locations on the host, such as /etc/cron.d. Consequently, this could enable the attacker to run their payload with host root privileges, effectively violating the isolation intended by Kata Containers. This vulnerability was addressed in version 3.31.0.

Affected Version(s)

kata-containers < 3.31.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.