A vulnerability has been discovered in Kubelet, which can lead to privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202405-31 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Kubelet: Privilege Escalation Date: May 12, 2024 Bugs: #918665 ID: 202405-31 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Kubelet, which can lead to privilege escalation. Background ========== Kubelet is a Kubernetes Node Agent. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------ sys-cluster/kubelet < 1.28.5 > = 1.28.5 Description =========== A vulnerability has been discovered in Kubelet. Please review the CVE identifier referenced below for details. Impact ====== A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes. Workaround ========== There is no known workaround at this time. Resolution ========== All Kubelet users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-cluster/kubelet-1.28.5" References ========== [ 1 ] CVE-2023-5528 https://nvd.nist.gov/vuln/detail/CVE-2023-5528 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202405-31 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users'machines is of utmost importance to us. Any security concerns should be addressed to
The following updated rpms for Oracle Linux Cloud Native Environment 1.6 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Cloud Native Environment Security Advisory ELSA-2023-12355 https://linux.oracle.com/errata/ELSA-2023-12355.html The following updated rpms for Oracle Linux Cloud Native Environment 1.6 have been uploaded to the Unbreakable Linux Network: x86_64: istio-1.16.4-1.el7.x86_64.rpm istio-istioctl-1.16.4-1.el7.x86_64.rpm kubelet-1.25.7-2.el7.x86_64.rpm kubectl-1.25.7-2.el7.x86_64.rpm kubeadm-1.25.7-2.el7.x86_64.rpm olcnectl-1.6.1-8.el7.x86_64.rpm olcne-agent-1.6.1-8.el7.x86_64.rpm olcne-api-server-1.6.1-8.el7.x86_64.rpm olcne-utils-1.6.1-8.el7.x86_64.rpm olcne-nginx-1.6.1-8.el7.x86_64.rpm olcne-prometheus-chart-1.6.1-8.el7.x86_64.rpm olcne-grafana-chart-1.6.1-8.el7.x86_64.rpm olcne-istio-chart-1.6.1-8.el7.x86_64.rpm olcne-olm-chart-1.6.1-8.el7.x86_64.rpm olcne-gluster-chart-1.6.1-8.el7.x86_64.rpm olcne-oci-ccm-chart-1.6.1-8.el7.x86_64.rpm olcne-metallb-chart-1.6.1-8.el7.x86_64.rpm olcne-calico-chart-1.6.1-8.el7.x86_64.rpm olcne-multus-chart-1.6.1-8.el7.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//istio-1.16.4-1.el7.src.rpm https://oss.oracle.com:443/ol7/SRPMS-updates//kubernetes-1.25.7-2.el7.src.rpm https://oss.oracle.com:443/ol7/SRPMS-updates//olcne-1.6.1-8.el7.src.rpm Related CVEs: CVE-2022-27487 CVE-2022-27488 CVE-2022-27491 CVE-2022-27492 CVE-2022-27493 CVE-2022-27496 Description of changes: istio [1.16.4-1] - Added Oracle specific files for 1.16.4-1 kubernetes [1.25.7-2] - libct/cg: add misc controller to v1 drivers (upstream runc patch) olcne [1.6.1-8] - Update Istio config to include 1.15.7 to support upgrade from 1.5.x to 1.6.x [1.6.1-7] - Bugfix:Append a slash in oci-instance-metada query url [1.6.1-6] - Fixed helm installation in OLCNE upgrade [1.6.1-5] - Deprecate oci-private-key in favour of oci-private-key-file - Updated olcne_version argument in olcnectl provision to support [1.6.1-4] - Update Istio version to 1.16.4 to addressCVE's - CVE-2022-27496 - CVE-2022-27488 - CVE-2022-27493 - CVE-2022-27492 - CVE-2022-27491 - CVE-2022-27487 [1.6.1-3] - Resolved the issue to install multiple network cards using multus [1.6.1-2] - Update kubelet for upstream runc misc cgroups patch [1.6.1-1] - Fix the bug olcnectl provision fails if ol8_developer does not exist _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.