Missing Authorization in Kata Containers - CVE-2026-64676
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to tamper with in-guest memory management and cause availability and performance degradation of the confidential workload.
The vulnerability exists due to missing authorization in mem-agent ttRPC methods when handling ttRPC API calls. A remote attacker can invoke the affected methods unconditionally to tamper with in-guest memory management and cause availability and performance degradation of the confidential workload.
Only deployments with the mem-agent feature enabled are vulnerable.