CVE-2026-47243General

MEDIUMCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. In this configuration, Kata runs the host virtiofsd as root with --sandbox none --seccomp none, so an attacker with root-equivalent access inside the guest can bypass the guest virtio-fs client entirely by taking over the virtio-fs PCI device and building a virtqueue in userspace to submit raw FUSE requests directly to the host virtiofsd. A crafted FUSE_SYMLINK request whose new symlink name is an absolute host path is honored outside the configured shared directory, allowing guest root to create root-owned symlinks in sensitive host locations such as /etc/cron.d. By pointing such a symlink at a guest-controlled crontab payload reachable through a live runtime process's mount namespace, the attacker causes the host cron daemon to execute that payload as host root, crossing the Kata isolation boundary. This issue is fixed in version 3.31.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-36

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-08-08)
  • 9 total mentions across 6 days

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-05-21: 1Mentions · 2026-05-23: 1Mentions · 2026-05-28: 2Mentions · 2026-06-16: 1Mentions · 2026-06-26: 1Mentions · 2026-08-08: 3PoC Mentioned / Linked · 2026-05-28: 2Exploit Tool / Code · 2026-05-28: 2Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-28: 2Technical Details · 2026-06-26: 1Technical Details · 2026-08-08: 105-2105-2305-2806-1606-2608-08
Signal classification3 categories
General
444.4%
Disclosure
333.3%
PoC
222.2%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-211
General1
2026-05-231
Disclosure1
2026-05-282
PoC2
2026-06-161
General1
2026-06-261
Disclosure1
2026-08-083
Disclosure1General2
Full discourse9 posts
  • NanoVMs@nanovms
    General

    this week in containers don't contain we see an interesting escape - CVE-2026-47243 - in kata's runtime-rs - if you're gonna kata you might as well go full unikernel

    Post summary

    The tweet alerts to a new CVE (2026-47243) affecting Kata's runtime-rs and hints at an escape, but offers no further technical detail, PoC, or patch information.

    120113749
    2.2K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-47243: Kata Containers runtime-rs 3.30: virtiofsd symlink escape https://www.openwall.com/lists/oss-security/2026/05/21/14 runs virtiofsd as root with --sandbox none --seccomp none. A raw FUSE_SYMLINK request lets guest root create host-root-owned symlinks in sensitive host paths. Fixed in 3.31.0.

    Post summary

    CVE-2026-47243 details a virtiofsd symlink escape in Kata Containers 3.30 that allows guest root to create host‑root symlinks; the issue is fixed in 3.31.0.

    010811.2K
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Explore the critical Kata Containers container escape vulnerability (CVE-2026-47243). Technical details and PoC exploit code are now fully public. #Cybersecurity #CloudSecurity #ContainerEscape #KataContainers #Infosec #CVE202647243 https://securityonline.info/kata-containers-container-escape-cve-2026-47243/ https://t.co/bpF0Zd63PH

    Post summary

    The post announces that the critical Kata Containers container escape vulnerability (CVE‑2026‑47243) is publicly documented with technical details and a PoC exploit code now available.

    100311.0K
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Kata Containersにホストrootへのエスケープ脆弱性。CVE-2026-47243。PoC(攻撃の概念実証コード)公開済み。runtime-rsシステムパスが攻撃表面。修正版提供あり。 https://securityonline.info/kata-containers-container-escape-cve-2026-47243/

    Post summary

    CVE‑2026‑47243 in Kata Containers allows host‑root escape; a PoC has been released and a fix is already available.

    01010932
    7.5K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    📦 Kata Containers guest-to-host escape vulnerability CVE-2026-47243 affects Kata Containers before 3.31.0. A flaw in the runtime-rs virtio-fs path could allow an attacker with root privileges inside a guest to escape the isolation boundary and reach root on the host. 🔎 Source: MITRE CVE / VulDB. #Containers #CloudSecurity #KataContainers #CVE #CyberSecurity

    Post summary

    The post announces CVE‑2026‑47243, a guest‑to‑host escape vulnerability in Kata Containers that permits a malicious guest with root rights to elevate privileges to the host.

    0000045
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-47243 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, t… https://www.cve.org/CVERecord?id=CVE-2026-47243 ----- Traducción: CVE-2026-47243 Kat… http://infoflow.cloud`

    Post summary

    The tweet merely references the CVE ID and provides a link, offering no substantive details about the vulnerability or its exploitation.

    0000041
    98 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-47243 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, t… https://www.cve.org/CVERecord?id=CVE-2026-47243

    Post summary

    The post references CVE‑2026‑47243 as affecting Kata Containers before version 3.31.0, but provides no exploitation details, patches, or technical specifics.

    00000850
    57.9K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    CVE-2026-47243: Kata Containers guest-root to host-root escape via virtiofs https://www.openwall.com/lists/oss-security/2026/05/21/14?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet shares a link to a discussion about CVE‑2026‑47243, describing a privilege‑escalation vulnerability in Kata Containers that allows guest‑root to host‑root escape via virtiofs. No PoC, exploit code, patch, or active exploitation claim is provided.

    0000051
    1.5K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-47243: Kata Containers runtime-rs virtiofs Symlink Escape - What It Means for Your Business and How to Respond https://hubs.li/Q04lz0bN0

    Post summary

    The excerpt contains only the CVE title and a link, offering no substantive details, PoC, exploit, patch information, or evidence of active exploitation.

    0000032
    31 followersView on X

Explore more