kubelet-started container uid changes to root after first restart or if image is already pulled to the node
Published Aug 29, 2019
7.8
HIGHCVSS 3.0
EPSS 0.60%
Description
In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubelet will refuse to start the container as root. If the pod did not specify mustRunAsNonRoot: true, the kubelet will run the container as uid 0.
Affected products
-
- Version v1.13.6StatusaffectedConstraints-
- Version v1.14.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
- 1.13.6
- 1.14.2
No data.
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.6
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.7
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
k8s.io/kubernetes/cmd/kubelet
Go
Introduced 1.14.0 Fixed 1.14.3k8s.io/kubernetes/cmd/kubelet
Go
Introduced 1.13.0 Fixed 1.13.7k8s.io/kubernetes
Go
Introduced 1.13.0 Fixed 1.13.7k8s.io/kubernetes
Go
Introduced 1.14.0 Fixed 1.14.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes/cmd/kubelet | 1.14.0 | 1.14.3 |
| Go | k8s.io/kubernetes/cmd/kubelet | 1.13.0 | 1.13.7 |
| Go | k8s.io/kubernetes | 1.13.0 | 1.13.7 |
| Go | k8s.io/kubernetes | 1.14.0 | 1.14.3 |
Remediation
Vendor solution
Specify runAsUser directives in pods to control the uid a container runs as. Specify mustRunAsNonRoot:true directives in pods to prevent starting as root (note this means the attempt to start the container will fail on affected kubelet versions).
Red Hat statement
This vulnerability only affects upstream Kubernetes versions 1.13.6 and 1.14.2. All released versions of Red Hat OpenShift Container Platform and Red Hat Gluster Storage 3 are not affected by this flaw as they do not contain the vulnerable code.
Red Hat mitigation
There are two potential mitigations to this issue: 1. Downgrade to kubelet v1.13.5 or v1.14.1 as instructed by your Kubernetes distribution. 2. Set RunAsUser on all pods in the cluster that should not run as root. This is a Security Context feature; the docs are at https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (GHSA) ▾
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.60% (0.00599) | 46.72th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.60% (0.00599) | 47.33th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.40% (0.01404) | 49.02th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v1 |
| Jan 6, 2022 | 2.74% (0.02742) | 62.72th | v1 |
| Jan 5, 2022 | 0.62% (0.00624) | 46.35th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (11)
- https://access.redhat.com/security/cve/CVE-2019-11245 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1715726 Issue Tracking
- https://discuss.kubernetes.io/t/security-regression-in-kubernetes-kubelet-v1-13-6-and-v1-14-2-only-cve-2019-11245/6584
- https://github.com/advisories/GHSA-r76g-g87f-vw8f Advisory
- https://github.com/kubernetes/kubernetes/issues/78308 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://github.com/kubernetes/kubernetes/pull/76665
- https://github.com/kubernetes/kubernetes/pull/76665/commits/26e3c8674e66f0d10170d34f5445f0aed207387f
- https://nvd.nist.gov/vuln/detail/CVE-2019-11245
- https://pkg.go.dev/vuln/GO-2024-2780
- https://security.netapp.com/advisory/ntap-20190919-0003 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2019-11245
Change history (0)
No recorded changes yet.