PT-2026-69153 · Unknown · Kata Containers
CVE-2026-64676
·
Published
2026-08-07
·
Updated
2026-08-08
CVSS v3.1
5.7
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Kata Containers versions prior to 4.0.0
Description
The kata-agent contains an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo) deployments, the kata-agent uses an OPA/Rego-based AgentPolicy to authorize ttRPC API calls, which serves as the security boundary against untrusted hosts. Two ttRPC methods associated with the mem-agent feature lack this authorization check. If the mem-agent is enabled, an untrusted host can unconditionally invoke these methods to manipulate in-guest memory management by forcing swap, aggressive eviction, or compaction. This can lead to performance degradation and impact the availability of the confidential workload. This issue does not allow for code execution or memory disclosure.
Recommendations
Update to version 4.0.0.
As a temporary mitigation, ensure the mem-agent feature remains disabled.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kata Containers