Kata Containers Initdata Verification Bypass Vulnerability on TDX Systems

Vulnerability

A vulnerability in Kata Containers versions through 3.20.0 allows a malicious host to bypass initdata verification on TDX systems with confidential guests. This is achieved by selectively failing I/O operations, enabling the host to skip crucial verification steps. As a result, an attacker can launch arbitrary workloads while successfully attesting to Trustee as if it were any benign workload. The issue arises because the Kata agent can be manipulated to overlook verification, creating a risk of unauthorized workload execution under false pretenses.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of workloads in a confidential guest environment, with the ability to manipulate attestation statements, potentially undermining the integrity of the workload verification process.

Reproduction

The vulnerability can be reproduced on a TDX system running Kata Containers versions through 3.20.0. A malicious host can tamper with the guest's I/O operations to induce errors that bypass initdata verification. Once the verification is skipped, the Kata agent will accept and execute workloads without proper oversight, allowing for arbitrary tasks to be performed under the guise of a trusted process.

Remediation

Users can upgrade to Kata Containers version 3.21.0 or later, where this vulnerability has been patched.

Added: Sep 23, 2025, 9:18 PM
Updated: Sep 23, 2025, 9:18 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
7.5
exploitability
2.5
remediation
7.7
relevance
0.6
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.