kubernetes: Incorrect rule injection in CNI portmap plugin
Published Apr 2, 2019
7.5
HIGHCVSS 3.0
EPSS 3.16%
Description
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
Affected products
No data.
Configuration 1
- < 0.7.5
- < 1.11.9
- ≥ 1.12.0 · < 1.12.7
- ≥ 1.13.0 · < 1.13.5
- 1.13.6
- 1.14.0
- 1.14.0
- 1.14.0
- 1.14.0
- 1.14.0
- 1.14.0
- 1.14.0
- 1.14.0
Configuration 2
- n/a
No data.
Red Hat Enterprise Linux 7 Extras
containernetworking-plugins-0:0.7.5-2.el7
Fixed · RHBA-2019:0862
Red Hat Enterprise Linux 8
container-tools:rhel8-8010020190927090915.4985cc55
Fixed · RHSA-2019:3403
Red Hat Enterprise Linux 8
container-tools:1.0/containernetworking-plugins
Out of support scope
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.4
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.5
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.6
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.7
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extras | containernetworking-plugins-0:0.7.5-2.el7 | Fixed | RHBA-2019:0862 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8010020190927090915.4985cc55 | Fixed | RHSA-2019:3403 |
| Red Hat Enterprise Linux 8 | container-tools:1.0/containernetworking-plugins | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.5 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While this issue affects the CNI portmap plugin that is bundled with Kubernetes, it does not affect OpenShift Container Platform as the vulnerable plugin is not included. It also does not affect the version of Kubernetes (embedded in heketi) shipped with Red Hat Gluster Storage 3 as it does not contain the vulnerable code.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.16% (0.03159) | 87.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.12% (0.03119) | 86.10th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.50% (0.00496) | 62.98th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.54% (0.01542) | 69.68th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.30% (0.00299) | 51.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.23% (0.00234) | 62.30th | v3 (v2023.03.01) |
| Mar 26, 2024 | 0.21% (0.00206) | 57.87th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.14% (0.00142) | 48.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.18% (0.07176) | 80.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.36% (0.05363) | 79.74th | v1 |
| Jan 6, 2022 | 5.36% (0.05363) | 79.54th | v1 |
| Sep 1, 2021 | 1.25% (0.01247) | 68.62th | v1 |
| Apr 14, 2021 | 1.25% (0.01247) | 0.00th | v1 |
References (10)
- https://access.redhat.com/errata/RHBA-2019:0862 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-9946 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1692712 Issue Tracking
- https://discuss.kubernetes.io/t/announce-security-release-of-kubernetes-affecting-certain-network-configurations-with-cni-releases-1-11-9-1-12-7-1-13-5-and-1-14-0-cve-2019-9946/5713
- https://github.com/containernetworking/plugins/pull/269#issuecomment-477683272 x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCN66VYB3XS76SYH567SO7N3I254JOCT/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGOOWAELGH3F7OXRBPH3HCNZELNLXYTW/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-9946
- https://security.netapp.com/advisory/ntap-20190416-0002/ x_refsource_CONFIRMPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9946
Change history (0)
No recorded changes yet.