---
id: CVE-2026-44210
title: >-
  kata-containers: Kata Containers: Privilege escalation and information
  disclosure via command-line argument injection (CVE-2026-44210)
summary: >-
  A flaw was found in Kata Containers, an open-source project that provides
  lightweight virtual machines (VMs) for containers. A user with privileges to
  create pods can inject malicious command-line arguments into the virtiofsd
  process, whic…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-88
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - openshift_container_platform 4
patched:
  - github.com/kata-containers/kata-containers 0.0.0-20260519062212-ffa59ce3aa78
published: '2026-07-23'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T16:52:10+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44210.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44210.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-44210'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2506563'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-44210'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44210'
  - url: >-
      https://github.com/kata-containers/kata-containers/commit/ffa59ce3aa7877d067c9a372df0c329a23a01744
  - url: >-
      https://github.com/kata-containers/kata-containers/security/advisories/GHSA-rr59-xxvx-96qr
  - url: 'https://github.com/kata-containers/kata-containers'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00502
epssPercentile: 0.42025
aliases:
  - GHSA-rr59-xxvx-96qr
  - GO-2026-5638
ecosystem: go
ingestedAt: '2026-07-28T19:09:13.113Z'
---

## Overview

A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, which manages shared file systems. This injection allows an attacker to override the shared directory, enabling the guest VM to access the entire host's root filesystem. When combined with another default configuration, this vulnerability allows an attacker to read and write any file on the host system, leading to significant information disclosure and potential privilege escalation.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44210.json)

**kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection** — rated Important by Red Hat. Released 2026-07-23, updated 2026-09-22.

Affected:

- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat OpenShift Container Platform 4

## Remediation

Affected

## Package advisory (CVE-2026-44210)

Affected packages:

- `github.com/kata-containers/kata-containers < 0.0.0-20260519062212-ffa59ce3aa78`

Patched in:

- `github.com/kata-containers/kata-containers 0.0.0-20260519062212-ffa59ce3aa78`

Source: https://osv.dev/vulnerability/GHSA-rr59-xxvx-96qr
