Описание
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.
A flaw was found in Distribution, a toolkit used for managing container content. When specific caching and deletion features are enabled, a remote attacker can exploit a vulnerability that allows previously deleted content to become readable again. This occurs because the system does not fully remove all references to the deleted data, leading to unauthorized information disclosure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-9-rhel9 | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-framework-tools-rhel9 | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-registry | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift-clients | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | redhat/redhat-operator-index | Affected | ||
| Red Hat OpenShift Container Platform 4.12 | openshift4/ose-operator-lifecycle-manager | Fixed | RHSA-2026:26529 | 25.06.2026 |
| Red Hat OpenShift Container Platform 4.13 | openshift4/ose-operator-lifecycle-manager | Fixed | RHSA-2026:26543 | 25.06.2026 |
| Red Hat OpenShift Container Platform 4.14 | openshift4/ose-operator-lifecycle-manager | Fixed | RHSA-2026:28893 | 01.07.2026 |
| Red Hat OpenShift Container Platform 4.15 | openshift4/ose-operator-lifecycle-manager-rhel9 | Fixed | RHSA-2026:23234 | 11.06.2026 |
| Red Hat OpenShift Container Platform 4.16 | openshift4/ose-operator-lifecycle-manager-rhel9 | Fixed | RHSA-2026:25045 | 17.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.
Distribution is a toolkit to pack, ship, store, and deliver container ...
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
Уязвимость функции распространения инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с ошибками разграничения доступа, позволяющая нарушителю повысить свои привилегии
EPSS
7.5 High
CVSS3