Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-47243: Kata Containers: Guest Can Create Host Root Symlinks
CVE-2026-47243 · published 1 month ago
Summary
An attacker with root access inside a Kata Containers guest can create symbolic links on the host that allow them to execute code as the host root user. This is a risk because it could be used to take control of the host system. To mitigate this risk, ensure that rootless mode is enabled in your Kata Containers configuration.
What to do
- Update github.com kata-containers to version 0.0.0-20260519062212-ffa59ce3aa78.
- Update kata-containers github.com/kata-containers/kata-containers to version 0.0.0-20260519062212-ffa59ce3aa78.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | kata-containers |
< 0.0.0-20260519062212-ffa59ce3aa78 Fix: upgrade to 0.0.0-20260519062212-ffa59ce3aa78
|
| Go | kata-containers | github.com/kata-containers/kata-containers |
< 0.0.0-20260519062212-ffa59ce3aa78 Fix: upgrade to 0.0.0-20260519062212-ffa59ce3aa78
|
| – | kata-containers | kata-containers | < 3.31.0 |
Original advisory text
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. In this configuration, Kata runs the host virtiofsd as root with --sandbox none --seccomp none, so an attacker with root-equivalent access inside the guest can bypass the guest virtio-fs client entirely by taking over the virtio-fs PCI device and building a virtqueue in userspace to submit raw FUSE requests directly to the host virtiofsd. A crafted FUSE_SYMLINK request whose new symlink name is an absolute host path is honored outside the configured shared directory, allowing guest root to create root-owned symlinks in sensitive host locations such as /etc/cron.d. By pointing such a symlink at a guest-controlled crontab payload reachable through a live runtime process's mount namespace, the attacker causes the host cron daemon to execute that payload as host root, crossing the Kata isolation boundary. This issue is fixed in version 3.31.0.
References
- https://github.com/kata-containers/kata-containers/commit/ffa59ce3aa7877d067c9a3...
- https://github.com/kata-containers/kata-containers/releases/tag/3.31.0
- https://github.com/advisories/GHSA-2gv2-cffp-j227
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47243... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-47243 Vendor Advisory
- https://github.com/kata-containers/kata-containers/security/advisories/GHSA-2gv2...
- http://www.openwall.com/lists/oss-security/2026/05/21/14
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-22Path Traversal
CWE-36Absolute Path Traversal
Timeline
Published7 Aug 2026
Updated27 Sep 2026
First seen27 May 2026
Sources
GHSA-2gv2-cffp-j227 · GHSA
CVE-2026-47243 · NVD
GO-2026-5042 · OSV
CVE-2026-47243 · MITRE
CVE-2026-47243 · OSV
Track software like this
Free during beta