Bugzilla – Bug 1172092
VUL-0: CVE-2020-2024: katacontainers: a malicious guest can trick the kata-runtime into unmounting any mount point on the host
Last modified: 2020-05-29 13:42:17 UTC
CVE-2020-2024 An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-2024 https://github.com/kata-containers/runtime/pull/2475 https://github.com/kata-containers/runtime/issues/2474 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2024
Hey Ralf, do you wanna take care of this? :)
Sure
Submitted: https://build.opensuse.org/request/show/810221 https://build.opensuse.org/request/show/810220