Kata Containers: CopyFile Policy Subversion via Symlinks
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.2epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:N/SA:N
Affected products
kata-containers · kata-containersReferences
https://access.redhat.com/errata/RHSA-2026:25200https://access.redhat.com/security/cve/CVE-2026-41326https://bugzilla.redhat.com/show_bug.cgi?id=2460859https://github.com/kata-containers/kata-containers/commit/1b9e49eb2763aa6ea6a99b276d3ff5e2c7f658f2https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cchttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41326.jsonhttp://www.openwall.com/lists/oss-security/2026/05/13/2