Impact
The vulnerability arises because the kata-agent fails to enforce the expected authorization check on two ttRPC methods related to the mem‑agent feature. An untrusted host can therefore invoke those methods regardless of the guest’s policy, allowing it to manipulate confidential‑guest memory by forcing swap, eviction, or compaction. The result is a degradation of availability and performance for the confidential workload; the flaw does not provide memory disclosure or code execution capabilities.
Affected Systems
Kata Containers, versions prior to 4.0.0, where the mem‑agent feature is enabled. The mem‑agent option is disabled by default, but if an administrator turns it on, the affected packages fall within the vulnerability scope.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog. An attacker needs host‑level access and the mem‑agent feature enabled to exploit the issue. Once these conditions are met, the host can induce resource contention inside the guest, impairing availability and performance. While the risk is moderate, the denial‑of‑service nature can disrupt confidential workloads, so remediation is advised promptly.
OpenCVE Enrichment