An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2024
Reference (s):
- https://github.com/kata-containers/runtime/issues/2474
- https://github.com/kata-containers/runtime/pull/2475