Skip to content
VulniPulse
Advisory severityHigh8.8Red Hat Linux

High [CVE-2026-50540] Arbitrary code execution via manipulated configuration path

This high-severity Red Hat Linux advisory covers CVE-2026-50540 affecting Confidential Compute Attestation, Red Hat OpenShift Container Platform 4.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-50540 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation.

The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host.

This issue is fixed in version 4.0.0. A flaw was found in Kata Containers, affecting both its Rust and Go runtimes.

An authenticated pod user can exploit this by setting the `io.katacontainers.config_path` annotation to an arbitrary configuration file on the host. This allows the attacker to control privileged runtime settings, leading to the execution of malicious binaries as root on the host system.

The primary consequence is arbitrary code execution with elevated privileges. This is an Important flaw in Kata Containers that allows an authenticated pod user to achieve arbitrary code execution as root on the host.

Affected products named by the advisory: Confidential Compute Attestation; Red Hat OpenShift Container Platform 4.

Affected versions
  • < 4.0.0

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Fixed versions
  • 4.0.0

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Mitigation

Upgrade to a fixed release: 4.0.0. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.