CRITICAL9.8
GHSA-6978-vg2j-cc9q
Improper Privilege Management and Execution with Unnecessary Privileges in Kata Containers
Quick fix
GHSA-6978-vg2j-cc9q — github.com/kata-containers/agent: upgrade to the fixed version with the command below.
go get github.com/kata-containers/agent@v1.9.1Details
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/kata-containers/agent
Introduced in:
0Fixed in: 1.9.1Fix
go get github.com/kata-containers/agent@v1.9.1Go/github.com/kata-containers/agent
Introduced in:
1.10.0Fixed in: 1.10.5Fix
go get github.com/kata-containers/agent@v1.10.5Go/github.com/kata-containers/agent
Introduced in:
1.11.0Fixed in: 1.11.1Fix
go get github.com/kata-containers/agent@v1.11.1Go/github.com/kata-containers/runtime
Introduced in:
0Fixed in: 1.9.1Fix
go get github.com/kata-containers/runtime@v1.9.1Go/github.com/kata-containers/runtime
Introduced in:
1.10.0Fixed in: 1.10.5Fix
go get github.com/kata-containers/runtime@v1.10.5Go/github.com/kata-containers/runtime
Introduced in:
1.11.0Fixed in: 1.11.1Fix
go get github.com/kata-containers/runtime@v1.11.1References
- https://nvd.nist.gov/vuln/detail/CVE-2020-2023[ADVISORY]
- https://github.com/kata-containers/agent/issues/791[WEB]
- https://github.com/kata-containers/runtime/issues/2488[WEB]
- https://github.com/kata-containers/agent/pull/792[WEB]
- https://github.com/kata-containers/runtime/pull/2477[WEB]
- https://github.com/kata-containers/runtime/pull/2487[WEB]
- https://github.com/kata-containers[PACKAGE]
- https://github.com/kata-containers/runtime/releases/tag/1.10.5[WEB]
- https://github.com/kata-containers/runtime/releases/tag/1.11.1[WEB]