The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade k3s | Aug 22, 2024 | Jul 23, 2020 |
| Debian | — | Upgrade kubernetes | Jul 30, 2024 | Jul 23, 2020 |
| Oracle_linux | — | Upgrade kubectlUpgrade olcne-agentUpgrade kubeadmUpgrade olcne-api-serverUpgrade kataUpgrade kubeletUpgrade olcnectlUpgrade kernel-uek-containerUpgrade olcne-nginxUpgrade kata-imageUpgrade olcne-utilsUpgrade kata-runtime | Jul 23, 2020 | Jul 23, 2020 |
| Redhat Openshift | — | Upgrade openshiftUpgrade atomic-openshift | Dec 29, 2020 | Jul 15, 2020 |
| Suse | — | Upgrade kubernetes-commonUpgrade kubernetes-client | Feb 4, 2022 | Jul 22, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 23, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub