Kube-controller-manager: malformed hpa v1 manifest causes crash
Published Nov 17, 2024
7.7
HIGHCVSS 3.1
EPSS 0.59%
Description
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
No data.
No data.
Red Hat OpenShift Container Platform 4.12
openshift-0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el8
Fixed · RHSA-2024:1267
Red Hat OpenShift Container Platform 4.13
openshift4/ose-cluster-kube-controller-manager-operator:v4.13.0-202402011837.p0.gdac7113.assembly.stream
Fixed · RHSA-2024:0741
Red Hat OpenShift Container Platform 4
microshift
Will not fix
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.12 | openshift-0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el8 | Fixed | RHSA-2024:1267 |
| Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-kube-controller-manager-operator:v4.13.0-202402011837.p0.gdac7113.assembly.stream | Fixed | RHSA-2024:0741 |
| Red Hat OpenShift Container Platform 4 | microshift | Will not fix | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Not affected | n/a |
k8s.io/kubernetes
Go
Introduced 0 Fixed 1.27.0-alpha.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | 0 | 1.27.0-alpha.1 |
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/errata/RHSA-2024:0741 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1267 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-0793 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2214402 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3260 Advisory
- https://github.com/advisories/GHSA-h7wq-jj8r-qm7p Advisory
- https://github.com/kubernetes/kubernetes/issues/107038#issuecomment-1911327145
- https://github.com/openshift/kubernetes/pull/1876
- https://nvd.nist.gov/vuln/detail/CVE-2024-0793
- https://pkg.go.dev/vuln/GO-2024-3277
- https://www.cve.org/CVERecord?id=CVE-2024-0793
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:0741 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:1267 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2024-0793 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2214402 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3260 | Advisory | |
| https://github.com/advisories/GHSA-h7wq-jj8r-qm7p | Advisory | |
| https://github.com/kubernetes/kubernetes/issues/107038#issuecomment-1911327145 | ||
| https://github.com/openshift/kubernetes/pull/1876 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-0793 | ||
| https://pkg.go.dev/vuln/GO-2024-3277 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-0793 |
Change history (0)
No recorded changes yet.