Exposure of Resource to Wrong Sphere in Kata Containers - CVE-2026-24054
Published: May 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service on the host system.
The vulnerability exists due to improper device handling in container rootfs mounting logic when processing a malformed container image or an image with no layers. A remote user can start a container with a malformed image or an image that contains no layers to cause a denial of service on the host system.
This affects deployments using the default overlayfs containerd snapshotter with the Kata runtime class, and may cause the host disk to be remounted as read-only.
Affected software
openEuler
Anolis OS
kata-containers
kata-containers-go
How to mitigate CVE-2026-24054
kata-containers - addressed in versions 1.11.1-18, 1.11.1-32, 3.2.0-15
kata-containers-go - update to 1.11.1-30
kata-containers - update to 3.28.0-1
External References
Related Security Bulletins
- openEuler 22.03 LTS SP4 update for kata-containers
- openEuler 24.03 LTS SP2 update for kata-containers
- openEuler 24.03 LTS SP1 update for kata-containers
- openEuler 24.03 LTS update for kata-containers
- openEuler 20.03 LTS SP4 update for kata-containers
- openEuler 24.03 LTS SP3 update for kata-containers
- openEuler 24.03 LTS SP3 update for kata-containers-go
- Denial of service in Kata Containers
- Anolis OS update for kata-containers