Uncontrolled Memory Allocation in Kubernetes - CVE-2020-8552
Published: March 31, 2020
Vulnerability identifier: #VU26474
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8552
CWE-ID: CWE-789
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the Kubernetes API server component due to improper allocation of memory. A remote attacker can send a specially crafted API request and cause a denial of service condition on the target system.
Affected software
Kubernetes
Red Hat OpenShift Container Platform
Fedora
toolbox (Red Hat package)
ignition (Red Hat package)
libnftnl (Red Hat package)
iptables (Red Hat package)
cri-o (Red Hat package)
origin
openshift (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
machine-config-daemon (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
dracut (Red Hat package)
systemd (Red Hat package)
ostree (Red Hat package)
rpm-ostree (Red Hat package)
IBM MQ Operator
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
IBM CICS TX Standard
IBM CICS TX Advanced
Red Hat OpenShift Container Platform
Fedora
toolbox (Red Hat package)
ignition (Red Hat package)
libnftnl (Red Hat package)
iptables (Red Hat package)
cri-o (Red Hat package)
origin
openshift (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
machine-config-daemon (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
dracut (Red Hat package)
systemd (Red Hat package)
ostree (Red Hat package)
rpm-ostree (Red Hat package)
IBM MQ Operator
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2020-8552
Install updates from vendor's website.
Kubernetes - addressed in versions 1.15.10, 1.16.7, 1.17.3
Red Hat OpenShift Container Platform - update to 4.3.9
toolbox (Red Hat package) - update to 0.0.7-1.rhaos4.3.el8
ignition (Red Hat package) - update to 0.34.0-4.rhaos4.3.git92f874c.el8
libnftnl (Red Hat package) - update to 1.1.5-4.el8
iptables (Red Hat package) - update to 1.8.4-10.el8
cri-o (Red Hat package) - addressed in versions 1.16.3-26.dev.rhaos4.3.git9aad8e4.el7, 1.16.3-28.dev.rhaos4.3.git9aad8e4.el8
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
origin - update to 3.11.2-1.fc32
openshift (Red Hat package) - addressed in versions 4.2.29-202004110432.git.0.f7d02c8.el8, 4.2.29-202004120346.git.0.d948116.el7, 4.3.9-202003230116.git.0.ebf9a26.el7, 4.3.9-202003230116.git.0.ebf9a26.el8
openshift-clients (Red Hat package) - addressed in versions 4.3.9-202003230116.git.0.3d3933c.el7, 4.3.9-202003230116.git.0.3d3933c.el8
openshift-kuryr (Red Hat package) - update to 4.3.9-202003230116.git.0.9f1e22e.el8
machine-config-daemon (Red Hat package) - update to 4.3.9-202003230116.git.0.26e7ac9.el8
atomic-enterprise-service-catalog (Red Hat package) - update to 4.3.9-202003230116.git.0.57d5c98.el7
openshift-ansible (Red Hat package) - update to 4.3.9-202003230116.git.0.6124c7d.el7
atomic-openshift-service-idler (Red Hat package) - update to 4.3.9-202003230116.git.13.7ac3e5c.el7
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10
dracut (Red Hat package) - update to 049-70.git20200228.el8
systemd (Red Hat package) - update to 239-27.el8
ostree (Red Hat package) - update to 2019.6-2.el8
rpm-ostree (Red Hat package) - update to 2019.6-8.el8
Red Hat OpenShift Container Platform - update to 4.3.9
toolbox (Red Hat package) - update to 0.0.7-1.rhaos4.3.el8
ignition (Red Hat package) - update to 0.34.0-4.rhaos4.3.git92f874c.el8
libnftnl (Red Hat package) - update to 1.1.5-4.el8
iptables (Red Hat package) - update to 1.8.4-10.el8
cri-o (Red Hat package) - addressed in versions 1.16.3-26.dev.rhaos4.3.git9aad8e4.el7, 1.16.3-28.dev.rhaos4.3.git9aad8e4.el8
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
origin - update to 3.11.2-1.fc32
openshift (Red Hat package) - addressed in versions 4.2.29-202004110432.git.0.f7d02c8.el8, 4.2.29-202004120346.git.0.d948116.el7, 4.3.9-202003230116.git.0.ebf9a26.el7, 4.3.9-202003230116.git.0.ebf9a26.el8
openshift-clients (Red Hat package) - addressed in versions 4.3.9-202003230116.git.0.3d3933c.el7, 4.3.9-202003230116.git.0.3d3933c.el8
openshift-kuryr (Red Hat package) - update to 4.3.9-202003230116.git.0.9f1e22e.el8
machine-config-daemon (Red Hat package) - update to 4.3.9-202003230116.git.0.26e7ac9.el8
atomic-enterprise-service-catalog (Red Hat package) - update to 4.3.9-202003230116.git.0.57d5c98.el7
openshift-ansible (Red Hat package) - update to 4.3.9-202003230116.git.0.6124c7d.el7
atomic-openshift-service-idler (Red Hat package) - update to 4.3.9-202003230116.git.13.7ac3e5c.el7
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10
dracut (Red Hat package) - update to 049-70.git20200228.el8
systemd (Red Hat package) - update to 239-27.el8
ostree (Red Hat package) - update to 2019.6-2.el8
rpm-ostree (Red Hat package) - update to 2019.6-8.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Kubernetes
- Red Hat OpenShift Container Platform 4 update for ose-openshift-apiserver-container
- Red Hat OpenShift Container Platform 4.2 update for openshift
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Uncontrolled Memory Allocation in Red Hat OpenShift Container Platform 4.3 packages
- Fedora 32 update for origin