CVE-2026-44210Patch(katacontainers / kata_containers)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch katacontainers kata_containers systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the `kernel_params` annotation (also enabled by default) to activate the agent debug console, the attacker can mount the host filesystem from inside the VM and read or write any file on the host, including /etc/shadow. Version 3.31.0 patches the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kata_containers

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Products
kata_containers

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-16: 2PoC Mentioned / Linked · 2026-08-16: 1Exploit Tool / Code · 2026-08-16: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 208-16
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • takenaka hiroya@Joe_Biden_ja
    Patch

    Kata Containers に CVSS 9.9。危険度を決めるのは点数ではなく PR:L の中身、つまり Pod を誰に作らせているかです。テナントに作成を許しているなら、期待した分離が成立しません。3.31.0 で修正、設定だけで効く緩和もあります。 https://cve.autoarticles.net/cve/CVE-2026-44210

    Post summary

    The text highlights a high‑severity CVE‑2026‑44210, describing its key vulnerability factor and confirming that version 3.31.0 resolves it, with a configuration‑based mitigation also available.

    0001049
    562 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    PoC

    Kata Containers の CVE-2026-44210 は、壊れたコードではなく既定で開いていた入口の問題。Pod のアノテーションから virtiofsd に引数が渡り、ホストのルートFSがゲストに出ます。設定を読んで判定する依存なしのスクリプトを置きました。 https://blog.hashito.biz/2026/08/16/kata-containers-cve-2026-44210-annotation-allowlist-audit/

    Post summary

    The blog post discloses Kata Containers CVE‑2026‑44210, explaining how Pod annotations can expose the host root filesystem through virtiofsd, and shares a PoC script that demonstrates the issue.

    0000058
    562 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkatacontainerskata_containers---

Explore more