CVE-2020-2026: Fedoraproject Fedora

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.

Affected products

  • Fedoraproject Fedora: version 31 only
  • Katacontainers Runtime: up to and including 1.9; from 1.10, before 1.10.5 (fixed in 1.10.5); from 1.11, before 1.11.1 (fixed in 1.11.1)

Published 2020-06-10. Last modified 2026-06-17.