CVE detail
CVE-2026-24834
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately achieving arbitrary code execution as root in said VM. The current understanding is this doesn’t impact the security of the Host or of other containers / VMs running on that Host (note that arm64 QEMU lacks NVDIMM read-only support: It is believed that until the upstream QEMU gains this capability, a guest write could reach the image file). Version 3.27.0 patches the issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24834.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comFeb 19, 2026, 5:24 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2441025bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 19, 2026, 5:24 PM - https://access.redhat.com/security/cve/CVE-2026-24834access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 19, 2026, 5:24 PM - https://github.com/kata-containers/kata-containers/security/advisories/GHSA-wwj6-vghv-5p64github.com
No excerpt available.
Exploitgithub.comFeb 19, 2026, 5:24 PM No excerpt available.
Exploitgithub.comFeb 19, 2026, 5:24 PM- https://github.com/kata-containers/kata-containers/commit/6a672503973bf7c687053e459bfff8a9652e16bfgithub.com
No excerpt available.
Exploitgithub.comFeb 19, 2026, 5:24 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-25817CVSS 3.5 · Low
Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not…
- CVE-2021-41091CVSS 6.3 · Medium
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`…
- CVE-2019-0073CVSS 6.6 · Medium
The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file permissions. This may allow another user on the Junos OS devi…
- CVE-2026-48499CVSS 9.3 · Critical
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach r…
- CVE-2026-64707CVSS 5.5 · Medium
A permissions issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS…
- CVE-2026-61892CVSS 8.7 · High
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.