Denial of service in Kubernetes
Moderate severity
GitHub Reviewed
Published
Apr 24, 2024
to the GitHub Advisory Database
•
Updated Jun 10, 2024
Package
Affected versions
>= 1.1.0, < 1.16.13
>= 1.17.0, < 1.17.9
>= 1.18.0, < 1.18.6
Patched versions
1.16.13
1.17.9
1.18.6
Description
Published by the National Vulnerability Database
Jul 23, 2020
Published to the GitHub Advisory Database
Apr 24, 2024
Reviewed
Apr 24, 2024
Last updated
Jun 10, 2024
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.
References