{"id":"AZL-94679","summary":"CVE-2026-50540 affecting package cri-o 1.30.1-1","details":"Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host. This issue is fixed in version 4.0.0.","modified":"2026-08-30T05:24:52Z","published":"2026-08-07T21:17:28Z","upstream":["CVE-2026-50540"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50540"}],"affected":[{"package":{"name":"cri-o","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/cri-o"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.30.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94679.json"}}],"schema_version":"1.9.0"}