{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44210.json"
      }
    ],
    "title": "kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection",
    "tracking": {
      "current_release_date": "2026-08-06T01:03:20+00:00",
      "generator": {
        "date": "2026-08-06T01:03:20+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.12"
        }
      },
      "id": "CVE-2026-44210",
      "initial_release_date": "2026-07-23T17:32:23.927000+00:00",
      "revision_history": [
        {
          "date": "2026-07-23T17:32:23.927000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-06T01:00:31+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-06T01:03:20+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift Container Platform 4",
                "product": {
                  "name": "Red Hat OpenShift Container Platform 4",
                  "product_id": "red_hat_openshift_container_platform_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Container Platform 4"
          },
          {
            "category": "product_version",
            "name": "kata-containers",
            "product": {
              "name": "kata-containers",
              "product_id": "kata-containers",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/kata-containers"
              }
            }
          },
          {
            "category": "product_version",
            "name": "kata-containers.src",
            "product": {
              "name": "kata-containers.src",
              "product_id": "kata-containers.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/kata-containers?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhcos",
            "product": {
              "name": "rhcos",
              "product_id": "rhcos",
              "product_identification_helper": {
                "purl": "pkg:generic/redhat/rhcos"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "kata-containers as a component of Red Hat OpenShift Container Platform 4",
          "product_id": "red_hat_openshift_container_platform_4:kata-containers"
        },
        "product_reference": "kata-containers",
        "relates_to_product_reference": "red_hat_openshift_container_platform_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "kata-containers.src as a component of Red Hat OpenShift Container Platform 4",
          "product_id": "red_hat_openshift_container_platform_4:kata-containers.src"
        },
        "product_reference": "kata-containers.src",
        "relates_to_product_reference": "red_hat_openshift_container_platform_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhcos as a component of Red Hat OpenShift Container Platform 4",
          "product_id": "red_hat_openshift_container_platform_4:rhcos"
        },
        "product_reference": "rhcos",
        "relates_to_product_reference": "red_hat_openshift_container_platform_4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-44210",
      "cwe": {
        "id": "CWE-88",
        "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')"
      },
      "discovery_date": "2026-07-23T18:02:02.136354+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2506563"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, which manages shared file systems. This injection allows an attacker to override the shared directory, enabling the guest VM to access the entire host's root filesystem. When combined with another default configuration, this vulnerability allows an attacker to read and write any file on the host system, leading to significant information disclosure and potential privilege escalation.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_openshift_container_platform_4:kata-containers",
          "red_hat_openshift_container_platform_4:kata-containers.src",
          "red_hat_openshift_container_platform_4:rhcos"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-44210"
        },
        {
          "category": "external",
          "summary": "RHBZ#2506563",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506563"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-44210",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44210"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-44210",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44210"
        },
        {
          "category": "external",
          "summary": "https://github.com/kata-containers/kata-containers/commit/ffa59ce3aa7877d067c9a372df0c329a23a01744",
          "url": "https://github.com/kata-containers/kata-containers/commit/ffa59ce3aa7877d067c9a372df0c329a23a01744"
        },
        {
          "category": "external",
          "summary": "https://github.com/kata-containers/kata-containers/security/advisories/GHSA-rr59-xxvx-96qr",
          "url": "https://github.com/kata-containers/kata-containers/security/advisories/GHSA-rr59-xxvx-96qr"
        }
      ],
      "release_date": "2026-07-23T17:32:23.927000+00:00",
      "remediations": [
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_openshift_container_platform_4:kata-containers",
            "red_hat_openshift_container_platform_4:kata-containers.src",
            "red_hat_openshift_container_platform_4:rhcos"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_openshift_container_platform_4:kata-containers",
            "red_hat_openshift_container_platform_4:kata-containers.src",
            "red_hat_openshift_container_platform_4:rhcos"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openshift_container_platform_4:kata-containers",
            "red_hat_openshift_container_platform_4:kata-containers.src",
            "red_hat_openshift_container_platform_4:rhcos"
          ]
        }
      ],
      "title": "kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection"
    }
  ]
}