<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T17:36:14.345468+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349745</id>
    <title>EUVD-2026-349745</title>
    <updated>2026-10-05T17:36:14.491645+00:00</updated>
    <content>EUVD-2026-349745</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47243</id>
    <title>fkie_cve-2026-47243</title>
    <updated>2026-10-05T17:36:14.491698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. In this configuration, Kata runs the host virtiofsd as root with --sandbox none --seccomp none, so an attacker with root-equivalent access inside the guest can bypass the guest virtio-fs client entirely by taking over the virtio-fs PCI device and building a virtqueue in userspace to submit raw FUSE requests directly to the host virtiofsd. A crafted FUSE_SYMLINK request whose new symlink name is an absolute host path is honored outside the configured shared directory, allowing guest root to create root-owned symlinks in sensitive host locations such as /etc/cron.d. By pointing such a symlink at a guest-controlled crontab payload reachable through a live runtime process's mount namespace, the attacker causes the host cron daemon to execute that payload as host root, crossing the Kata isolation boundary. This issue is fixed in version 3.31.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2gv2-cffp-j227</id>
    <title>GHSA-2gv2-cffp-j227 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs</title>
    <updated>2026-10-05T17:36:14.491743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/kata-containers/kata-containers</p>
<p>### Summary</p>
<p>In the runtime-rs standalone virtio-fs path, verified here with QEMU (and verified with Cloud Hypervisor too), Kata Containers runs host `virtiofsd` as root with:</p>
<p>```
--sandbox none --seccomp none
```</p>
<p>If an attacker has root-equivalent execution inside the Kata guest VM, they can send raw FUSE requests directly to the host `virtiofsd`. With the tested runtime-rs virtio-fs configuration, a raw `FUSE_SYMLINK` request whose new symlink name is an absolute host path is honored outside the virtio-fs shared directory.</p>
<p>This lets guest root create host-root owned symlinks in sensitive host paths. The PoC created here will create symlinks in the host `/etc/cron.d` directory, causing host cron to execute a guest-controlled payload as host root.</p>
<p>Impact: guest root can execute code as host root.</p>
<p>### Affected configuration</p>
<p>The verified host used:</p>
<p>```
/opt/kata/share/defaults/kata-containers/runtime-rs/configuration-qemu-runtime-rs.toml</p>
<p>rootless = false
shared_fs = "virtio-fs"
virtio_fs_daemon = "/opt/kata/libexec/virtiofsd"
hypervisor_name = "qemu"
debug_console_enabled = false
```</p>
<p>Pinned upstream references, using Kata Containers `main` commit `2ffd1538a296cff93a357bfba0dfca747480a1f8`:</p>
<p>- runtime-rs standalone virtio-fs adds [`--sandbox none --seccomp none`](https://github.com/kata-containers/kata-containers/blob/2ffd1538a296cff93a357bfba0dfca747480a1f8/src/runtime-rs/crates/resource/src/share_fs/share_virtio_fs_standalone.rs#L82-L92) to the `virtiofsd` command li…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2gv2-cffp-j227"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-47243</id>
    <title>msrc_CVE-2026-47243 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs</title>
    <updated>2026-10-05T17:36:14.491810+00:00</updated>
    <content>msrc_CVE-2026-47243</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-47243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2527</id>
    <title>OESA-2026-2527 — kata-containers security update</title>
    <updated>2026-10-05T17:36:14.491831+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kata-containers</p>
<p>This is core component of Kata Container, to make it work, you need a isulad/docker engine.

Security Fix(es):</p>
<p>[&amp;apos;This vulnerability was fixed in Kata Containers 3.31.0:&amp;apos;, &amp;apos;Description:\n\nIn the runtime-rs standalone virtio-fs path, Kata Containers runs virtiofsd\nas root with --sandbox none --seccomp none.\n\nIf an attacker has root-equivalent execution inside the Kata guest VM,\nthey can send raw FUSE requests directly to the host virtiofsd.\n\nThen, a raw FUSE_SYMLINK request whose new symlink name is\nan absolute host path is honored outside the virtio-fs shared directory.\n\nThis lets guest root create host-root-owned symlinks in sensitive host paths.\n\nCVE: CVE-2026-47243\nGHSA: GHSA-2gv2-cffp-j227\n\nOriginal report:&amp;apos;, &amp;apos;---\nAurelien Bombo\nKata Containers Vulnerability Management Team&amp;apos;](CVE-2026-47243)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2527"/>
  </entry>
</feed>
