PT-2026-99445 · Containerd+3 · Kubernetes Containerd+3
CVSS v4.0
5.1
Medium
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Contrast versions prior to 1.9.1
Description
On bare-metal deployments, an untrusted host can write arbitrary file trees below a mount point inside a confidential container if the image declares at least one VOLUME (specified via the
config.volumes in the OCI image configuration) for which no Kubernetes mount exists. This occurs because containerd adds a mount point when Kubernetes sets none, allowing the runtime to push data to the Kata agent, which compromises the integrity of directories critical to application functionality.Recommendations
Update to version 1.9.1, which disallows this configuration in
contrast generate.Exploit
Fix
Files Accessible to External Parties
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Contrast
Kata
Kubernetes
Kubernetes Containerd