Improper Check for Unusual or Exceptional Conditions in Kata Containers - CVE-2025-58354
Published: May 22, 2026
Kata Containers
Detailed vulnerability description
The vulnerability allows a remote user to launch arbitrary workloads while attesting successfully as a benign workload.
The vulnerability exists due to improper check for unusual or exceptional conditions in the Kata agent attestation agent presence check when handling I/O errors during rootfs access. A remote privileged user can selectively fail I/O operations to skip initdata verification and launch arbitrary workloads while attesting successfully as a benign workload.
The issue applies only to CoCo variants using rootfs and dm-verity, and does not affect cases where guest component binaries are stored in the initrd.