Exposure of Resource to Wrong Sphere in Kata Containers - CVE-2026-24054

 

Exposure of Resource to Wrong Sphere in Kata Containers - CVE-2026-24054

Published: May 22, 2026


Vulnerability identifier: #VU132134
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24054
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service on the host system.

The vulnerability exists due to improper device handling in container rootfs mounting logic when processing a malformed container image or an image with no layers. A remote user can start a container with a malformed image or an image that contains no layers to cause a denial of service on the host system.

This affects deployments using the default overlayfs containerd snapshotter with the Kata runtime class, and may cause the host disk to be remounted as read-only.


Affected software

Kata Containers
openEuler
Anolis OS
kata-containers
kata-containers-go

How to mitigate CVE-2026-24054

Install security update from vendor's website.

Kata Containers - update to 3.26.0
kata-containers - addressed in versions 1.11.1-18, 1.11.1-32, 3.2.0-15
kata-containers-go - update to 1.11.1-30
kata-containers - update to 3.28.0-1

External References

Related Security Bulletins