CVE-2026-46695
Read-only volume remount bypass via guest CAP_SYS_ADMIN
描述
Affected versions of `boxlite` mount host directories shared via virtiofs as guest-side read-only by setting `MS_RDONLY` from the guest. Because the default guest capability set included `CAP_SYS_ADMIN`, untrusted code running inside a sandbox could execute `mount -o remount,rw <path>` to re-flag the share as read-write and then write through to the host filesystem — fully escaping the read-only contract `boxlite` advertised to callers. The fix in v0.9.0 enforces read-only at the hypervisor level via `krun_add_virtiofs3` (so the guest's `MS_RDONLY` is no longer the authoritative gate) and drops `CAP_SYS_ADMIN` from the default guest capability set (matching Docker's defaults). This is a sandbox-escape bug: `boxlite` is a sandboxing runtime, so the read-only invariant is part of its security contract. CVSS rated 10.0 by the upstream advisory.
如何修補 CVE-2026-46695
要修補 CVE-2026-46695,請將受影響套件升級到下列已修補版本。
- —升級至 0.9.0 或更新版本
CVE-2026-46695 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.9.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |