SB2026052279 - Denial of service in Kata Containers



SB2026052279 - Denial of service in Kata Containers

Published: May 22, 2026

Security Bulletin ID SB2026052279
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-24054)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to cause a denial of service on the host system.

The vulnerability exists due to improper device handling in container rootfs mounting logic when processing a malformed container image or an image with no layers. A remote user can start a container with a malformed image or an image that contains no layers to cause a denial of service on the host system.

This affects deployments using the default overlayfs containerd snapshotter with the Kata runtime class, and may cause the host disk to be remounted as read-only.


Remediation

Install update from vendor's website.