CVE-2022-31077
Malicious response from KubeEdge can crash CSI Driver controller server
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer dereference panic. As a consequence, the CSI Driver controller will be in denial of service. This bug has been fixed in Kubeedge 1.11.0, 1.10.1, and 1.9.3. Users should update to these versions to resolve the issue. At the time of writing, no workaround exists.
KubeEdge está construido sobre Kubernetes y extiende la orquestación de aplicaciones nativas en contenedores y la administración de dispositivos a los hosts en el Edge. En las versiones afectadas, una respuesta de mensaje maliciosa de KubeEdge puede bloquear el servidor del controlador CSI desencadenando un pánico de desreferencia de puntero nil. Como consecuencia, el controlador CSI Driver entrará en denegación de servicio. Este error ha sido corregido en Kubeedge versiones 1.11.0, 1.10.1 y 1.9.3. Los usuarios deben actualizar a estas versiones para resolver el problema. En el momento de escribir esto, no se presenta ninguna mitigación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-18 CVE Reserved
- 2022-06-27 CVE Published
- 2024-02-16 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/kubeedge/kubeedge/security/advisories/GHSA-x938-fvfw-7jh5 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/kubeedge/kubeedge/pull/3899 | 2022-07-11 | |
https://github.com/kubeedge/kubeedge/pull/3899/commits/5d60ae9eabd6b6b7afe38758e19bbe8137664701 | 2022-07-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linuxfoundation Search vendor "Linuxfoundation" | Kubeedge Search vendor "Linuxfoundation" for product "Kubeedge" | < 1.9.3 Search vendor "Linuxfoundation" for product "Kubeedge" and version " < 1.9.3" | - |
Affected
| ||||||
Linuxfoundation Search vendor "Linuxfoundation" | Kubeedge Search vendor "Linuxfoundation" for product "Kubeedge" | 1.10.0 Search vendor "Linuxfoundation" for product "Kubeedge" and version "1.10.0" | - |
Affected
| ||||||
Linuxfoundation Search vendor "Linuxfoundation" | Kubeedge Search vendor "Linuxfoundation" for product "Kubeedge" | 1.10.0 Search vendor "Linuxfoundation" for product "Kubeedge" and version "1.10.0" | beta0 |
Affected
|