Skip to content
Red HatCVE-2026-77176

A flaw was found in Kata Containers

High8.1CVE-2026-77176 · Published Aug 20, 2026 · updated Sep 1, 2026

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat multicloud-operators-subscription: information disclosure
High7.7Aug 20
A flaw was found in the multicloud-operators-subscription component
Critical9.9Aug 20
Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure
Low2.5Aug 20
Red Hat lighthouse: information disclosure
Medium5.4Aug 20
Red Hat Lighthouse. A remote attacker: privilege escalation
Low3.7Aug 20
A flaw was found in WildFly Elytron
High7.4Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.