High [CVE-2026-50540] Arbitrary code execution via manipulated configuration path
This high-severity Red Hat Linux advisory covers CVE-2026-50540 affecting Confidential Compute Attestation, Red Hat OpenShift Container Platform 4.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation.
The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host.
This issue is fixed in version 4.0.0. A flaw was found in Kata Containers, affecting both its Rust and Go runtimes.
An authenticated pod user can exploit this by setting the `io.katacontainers.config_path` annotation to an arbitrary configuration file on the host. This allows the attacker to control privileged runtime settings, leading to the execution of malicious binaries as root on the host system.
The primary consequence is arbitrary code execution with elevated privileges. This is an Important flaw in Kata Containers that allows an authenticated pod user to achieve arbitrary code execution as root on the host.
Affected products named by the advisory: Confidential Compute Attestation; Red Hat OpenShift Container Platform 4.
- < 4.0.0
Official advisory · high-confidence parse· fetched 16 days ago·verify at source
Mitigation
Upgrade to a fixed release: 4.0.0. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 16 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.