CVE-2019-11245: kubelet-started container uid changes to root after first restart or if image is already pulled to the node

Published May 24, 2019
·
Updated

In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubelet will refuse to start the container as root. If the pod did not specify mustRunAsNonRoot: true, the kubelet will run the container as uid 0.

Other sources

In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubelet will refuse to start the container as root. If the pod did not specify mustRunAsNonRoot: true, the kubelet will run the container as uid 0.

MITRE

Affected Software

6 affected componentsFixes available
redhat/kubernetes<1.13.7
1.13.7
redhat/kubernetes<1.14.3
1.14.3
go/k8s.io/kubernetes/cmd/kubelet>=1.13.0<1.13.7
1.13.7
go/k8s.io/kubernetes/cmd/kubelet>=1.14.0<1.14.3
1.14.3
Kubernetes kubernetes=1.13.6
Kubernetes kubernetes=1.14.2

Event History

Aug 29, 2019
CVE Published
via MITRE·12:22 AM
Data Sourced
via MITRE·12:22 AM
DescriptionSeverityWeakness
Apr 24, 2024
Advisory Published
via GitHub·08:03 PM

Frequently Asked Questions

1

What is CVE-2019-11245?

CVE-2019-11245 is a vulnerability in kubelet versions 1.13.6 and 1.14.2 that allows containers to run as root even if the pod specifies mustRunAsNonRoot: true.

2

How severe is CVE-2019-11245?

CVE-2019-11245 has a severity rating of 7.8 (high).

3

Which versions of Kubernetes are affected by CVE-2019-11245?

Kubernetes versions 1.13.6 and 1.14.2 are affected by CVE-2019-11245.

4

How can I fix CVE-2019-11245?

To fix CVE-2019-11245, upgrade to a version of kubelet that is not affected (e.g., versions higher than 1.14.2).

5

Are there any references for CVE-2019-11245?

Yes, you can find references for CVE-2019-11245 at the following links: [link1] [link2]

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203