CVE-2026-64676Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo) deployments, the kata-agent enforces an OPA/Rego-based AgentPolicy that must authorize every ttRPC API call, forming the security boundary that prevents an untrusted host from directing the confidential guest. Two ttRPC methods introduced with the mem-agent feature are missing this authorization check, so an untrusted host can invoke them unconditionally regardless of the guest's policy configuration. When mem-agent is enabled (off by default), this lets the host tamper with in-guest memory management by forcing swap, aggressive eviction, or compaction, resulting in attacker-controlled availability and performance degradation of the confidential workload entirely outside the agent-policy boundary. The impact does not include memory disclosure or code execution, and severity is bounded by the precondition that mem-agent must be explicitly enabled. This issue is fixed in version 4.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-08); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-08: 2Mentions · 2026-08-09: 2Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-09: 208-0808-09
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-082
Disclosure1General1
2026-08-092
Disclosure1Patch1
Full discourse4 posts
  • connect24h@connect24h
    Disclosure

    勘弁してくれ。Kata Containersの分離境界が両側から破られる。 CVE-2026-47243はvirtiofs経由でguest-rootからhost-rootへ脱出。CVE-2026-64676は未認可のmem-agent ttRPC methodにより、untrusted hostがconfidential guestのmemoryを改変できる。さらにCVE-2026-50540ではConfig Path Annotationから任意ファイルを読み込ませられる。 「VMだからcontainerより堅い」で止めると危ない。私の基盤レビューにも、Kataのversionだけでなくvirtiofsのmount、annotationの許可範囲、mem-agentの公開methodを分離して見る観点を追加する。Kata採用組織は、この3つを同じ境界破壊として棚卸しした方がいい。 ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64676

    Post summary

    The post discloses three new Kata Containers CVEs and outlines their exploitation vectors without providing PoCs, active exploitation evidence, or fixes.

    00002620
    5.7K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    ☁️ Kata Containers policy bypass affects confidential workloads CVE-2026-64676 affects Kata Containers before 4.0.0. Two memory-management API methods introduced with mem-agent lacked expected AgentPolicy authorization checks. In Confidential Containers environments, an untrusted host could influence guest memory-management behavior when the optional feature is enabled. ✅ Fixed in 4.0.0. 🔎 Source: Kata Containers / GitHub / CVE #KataContainers #ConfidentialComputing #CloudSecurity #CVE

    Post summary

    The notice reports a policy bypass (CVE-2026-64676) in Kata Containers that allows an untrusted host to influence guest memory management, and confirms the issue is fixed in version 4.0.0.

    0000037
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-64676 Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vul… https://www.cve.org/CVERecord?id=CVE-2026-64676 ----- Traducción: CVE-2026-64676 Kat… http://infoflow.cloud`

    Post summary

    The post briefly announces CVE-2026-64676 affecting Kata Containers’ kata-agent in versions prior to 4.0.0, but provides no additional technical details, patches, or exploitation information.

    0000046
    98 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-64676 Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vul… https://www.cve.org/CVERecord?id=CVE-2026-64676

    Post summary

    The post references CVE-2026-64676 involving the kata-agent in Kata Containers, but it provides none of the technical, exploit, or remediation details typically needed to classify it as a more specific alert.

    00000843
    57.9K followersView on X

Explore more