VDB
Sign up
HIGH8.8

GHSA-877x-32pm-p28x

Link Following in Kata Runtime

Quick fix

GHSA-877x-32pm-p28x — github.com/kata-containers/runtime: upgrade to the fixed version with the command below.

go get github.com/kata-containers/runtime@v1.9.1

Details

A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/kata-containers/runtime
Introduced in: 0Fixed in: 1.9.1
Fixgo get github.com/kata-containers/runtime@v1.9.1
Go/github.com/kata-containers/runtime
Introduced in: 1.10.0Fixed in: 1.10.6
Fixgo get github.com/kata-containers/runtime@v1.10.6
Go/github.com/kata-containers/runtime
Introduced in: 1.11.0Fixed in: 1.11.1
Fixgo get github.com/kata-containers/runtime@v1.11.1

References