SB2020051944 - Multiple vulnerabilities in Kata Containers



SB2020051944 - Multiple vulnerabilities in Kata Containers

Published: May 19, 2020 Updated: August 5, 2020

Security Bulletin ID SB2020051944
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper Preservation of Permissions (CVE-ID: CVE-2020-2025)

The vulnerability allows a remote attacker to take over all guest operating systems on the hypervisor.

Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and Firecracker based guests.


2) Link following (CVE-ID: CVE-2020-2024)

The vulnerability allows a remote attacker to perform a denial of service attack.

An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.


Remediation

Install update from vendor's website.