Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0426

Опубликовано: 13 фев. 2025
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

A flaw was found in Kubernetes. A large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may fill the Node's disk, potentially leading to a Node denial of service.

Отчет

OpenShift is not impacted by this vulnerability since the kubelet's unauthenticated read-only port is not enabled in that product.

Меры по смягчению последствий

To mitigate this vulnerability, disable the kubelet read-only port by setting readOnlyPort: 0 in /var/lib/kubelet/config.yaml and restarting kubelet. Additionally, disable container checkpointing by setting ContainerCheckpoint: false under featureGates. If using CRI-O, ensure enable_criu_support=false is configured in /etc/crio/crio.conf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-webhook-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/thanos-receive-controller-rhel9Not affected
Red Hat OpenShift Container Platform 4cri-toolsWill not fix
Red Hat OpenShift Container Platform 4openshiftWill not fix
Red Hat OpenShift Container Platform 4openshift4/cnf-tests-rhel8Will not fix
Red Hat OpenShift Container Platform 4openshift4/ingress-node-firewallWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2345617k8s.io/kubernetes: kubelet: node denial of service via kubelet checkpoint API

EPSS

Процентиль: 11%
0.00037
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 1 года назад

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

CVSS3: 6.2
nvd
около 1 года назад

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

CVSS3: 6.2
msrc
около 1 года назад

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

CVSS3: 6.2
debian
около 1 года назад

A security issue was discovered in Kubernetes where a large number of ...

CVSS3: 6.2
github
около 1 года назад

Node Denial of Service via kubelet Checkpoint API

EPSS

Процентиль: 11%
0.00037
Низкий

6.2 Medium

CVSS3