Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-32386

Опубликовано: 09 апр. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.

A flaw was found in Helm v3. In affected versions of Helm, a specially crafted chart archive file can cause Helm to use all available memory and have an out of memory (OOM) termination. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (for example, >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that any chart archive files being loaded by Helm do not contain files that are large enough to cause the Helm Client or SDK to use up available memory leading to a termination.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Fix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Fix deferred
Deployment Validation Operatordeployment-validation-operator-containerFix deferred
Multicluster Engine for Kubernetesmulticluster-engine/addon-manager-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/backplane-rhel8-operatorFix deferred
Multicluster Engine for Kubernetesmulticluster-engine/cluster-proxy-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorFix deferred
Multicluster Engine for Kubernetesmulticluster-engine/managed-serviceaccount-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/multicloud-manager-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/multicluster-engine-managed-serviceaccount-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2358755helm.sh/helm/v3: Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

EPSS

Процентиль: 22%
0.00073
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
12 месяцев назад

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.

CVSS3: 6.5
nvd
12 месяцев назад

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.

CVSS3: 6.5
msrc
около 1 месяца назад

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

CVSS3: 6.5
debian
12 месяцев назад

Helm is a tool for managing Charts. A chart archive file can be crafte ...

CVSS3: 6.5
github
12 месяцев назад

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

EPSS

Процентиль: 22%
0.00073
Низкий

6.5 Medium

CVSS3