CVE-2020-8557

Name
CVE-2020-8557
Description
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/kubernetes/kubernetes/issues/93032
Mailing List https://groups.google.com/g/kubernetes-security-announce/c/cB_JUsYEKyY/m/vVSO61AhBwAJ
CONFIRM https://security.netapp.com/advisory/ntap-20200821-0002/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* kubernetes >= None < 1.16.13
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* kubernetes >= 1.17.0 < 1.17.9
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* kubernetes >= 1.18.0 < 1.18.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
k3s edge-community 1.18.6.1-r0 None fixed
k3s 3.22-community 1.18.6.1-r0 None fixed
k3s 3.21-community 1.18.6.1-r0 None fixed
k3s 3.20-community 1.18.6.1-r0 None fixed
k3s 3.19-community 1.18.6.1-r0 None fixed
k3s 3.18-community 1.18.6.1-r0 None fixed
k3s 3.17-community 1.18.6.1-r0 None fixed