Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35172

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

A flaw was found in Distribution, a toolkit used for managing container content. When specific caching and deletion features are enabled, a remote attacker can exploit a vulnerability that allows previously deleted content to become readable again. This occurs because the system does not fully remove all references to the deleted data, leading to unauthorized information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Under investigation
Red Hat OpenShift Container Platform 4openshift4/ose-operator-framework-tools-rhel9Affected
Red Hat OpenShift Container Platform 4openshift4/ose-operator-registryAffected
Red Hat OpenShift Container Platform 4openshift-clientsUnder investigation
Red Hat OpenShift Container Platform 4redhat/redhat-operator-indexAffected
Red Hat OpenShift Container Platform 4.12openshift4/ose-operator-lifecycle-managerFixedRHSA-2026:2652925.06.2026
Red Hat OpenShift Container Platform 4.13openshift4/ose-operator-lifecycle-managerFixedRHSA-2026:2654325.06.2026
Red Hat OpenShift Container Platform 4.14openshift4/ose-operator-lifecycle-managerFixedRHSA-2026:2889301.07.2026
Red Hat OpenShift Container Platform 4.15openshift4/ose-operator-lifecycle-manager-rhel9FixedRHSA-2026:2323411.06.2026
Red Hat OpenShift Container Platform 4.16openshift4/ose-operator-lifecycle-manager-rhel9FixedRHSA-2026:2504517.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-524
https://bugzilla.redhat.com/show_bug.cgi?id=2455571github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion

EPSS

Процентиль: 37%
0.00455
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
nvd
4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
debian
4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container ...

CVSS3: 7.5
github
4 месяца назад

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость функции распространения инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с ошибками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 37%
0.00455
Низкий

7.5 High

CVSS3