OESA-2021-1084
Dashboard / Vulnerabilities / OESA-2021-1084
Summary: kata-containers security update
Details: This is core component of Kata Container, to make it work, you need a isulad/docker engine. Security Fix(es): An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.(CVE-2020-28914)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1084, https://nvd.nist.gov/vuln/detail/CVE-2020-28914
Affected packages
Package
Name: kata-containers
Purl: pkg:rpm/openEuler/kata-containers&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
