Uncontrolled Memory Allocation in Kubernetes - CVE-2020-8551
Published: March 31, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the Kubelet component due to improper allocation of memory in the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250. A remote attacker on the local network can cause a denial of service condition on the target system.
Affected software
Fedora
origin
openshift (Red Hat package)
How to mitigate CVE-2020-8551
origin - update to 3.11.2-1.fc32
openshift (Red Hat package) - addressed in versions 4.3.10-202003300855.git.0.da48c1d.el7, 4.3.10-202003300855.git.0.da48c1d.el8