Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77176— Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy

Quick assessment

Affected
Red Hat Red Hat OpenShift Container Platform 4
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Kata Containers 中发现了一个漏洞。在使用 genpolicy 为保密容器(Confidential Containers)的访客提供保护的配置中,恶意主机操作者可以利用对 CreateContainer 挂载和存储规则验证不足的问题,将任意的容器根文件系统路径挂载到敏感的主机位置,或者配置任意的内容,从而可能导致机密信息泄露,或使系统接受攻击者控制的数据输入。

CVSS 8.1 · High EPSS 0.41% · P34

Affected Version Matrix 2

VendorProduct Version RangeStatus
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77176

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-77176

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 6259 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-77176

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77176 (3)

Same Patch Batch · Red Hat · 2026-08-20 · 16 CVEs total

CVE-2026-67567 9.9 CRITICAL Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart ap
CVE-2026-66788 9.9 CRITICAL Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labels
CVE-2026-66785 9.9 CRITICAL Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowe
CVE-2026-11861 9.6 CRITICAL Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relations
CVE-2026-13097 9.1 CRITICAL Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniquenes
CVE-2026-66787 8.7 HIGH Lighthouse: lighthouse: cross-cluster dns spoofing via unvalidated endpointslice and servi
CVE-2026-18917 7.8 HIGH Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
CVE-2026-19582 7.8 HIGH Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe fi
CVE-2026-73137 7.7 HIGH Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secr
CVE-2026-73198 7.5 HIGH Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read
CVE-2026-73197 7.5 HIGH Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request b
CVE-2026-19611 7.4 HIGH Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: pass
CVE-2026-73199 6.5 MEDIUM Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`)
CVE-2026-77014 5.3 MEDIUM Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of
CVE-2026-73196 4.3 MEDIUM Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodi

IV. Related Vulnerabilities

V. Comments for CVE-2026-77176

No comments yet


Leave a comment