Database/Container, Kubernetes & orchestration

Kata Containers: Kata with Cloud Hypervisor allows a user to break the VM isolation boundary
CVSS 9.3CVE-2026-24834Container, Kubernetes & orchestrationcurated
Impact
Kata with Cloud Hypervisor allows a user to break the VM isolation boundary
Who can reach it
Any tenant workload running under Kata
What to do
Emergency Kata upgrade; drain and recreate Kata pods. The whole point of Kata is this boundary, so treat as critical
References
Related entries
- Kata Containers: runtime-rs standalone virtio-fs path is vulnerable to a guest-to-host escapeCVE-2026-47243 · Kata ContainersCritical
- Kata Containers: Malformed or layer-less container image breaks Kata's handlingCVE-2026-24054 · Kata ContainersHigh
- Kata Containers: Oversight in the CopyFile policy from v3.4.0 to v3.28.0CVE-2026-41326 · Kata ContainersHigh
- Kata Containers: A malicious host can circumvent guest protectionsCVE-2025-58354 · Kata ContainersMedium
- Kata Containers: Default configuration allows pod creators more than intendedCVE-2026-44210 · Kata ContainersMedium
- Kata Containers: kata-runtime host code execution via an untrusted input pathCVE-2026-50540 · Kata ContainersCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.