CVE-2020-8557: Kubernetes node disk Denial of Service by writing to container /etc/hosts

Published May 14, 2020
·
Updated

A flaw was found in Kubernetes, where the amount of disk space the /etc/hosts file can use is unconstrained . This flaw can allow attacker-controlled pods to cause a denial of service if they have permission to write to the node's /etc/hosts file.

Other sources

The kubelet sets up a file called etc-hosts for each pod, which is mounted in the containers as /etc/hosts. The file isn't counted against memory limits (as a tmpfs file would be) or ephemeral storage usage limits. The container can fill up the node disk on the node which it was scheduled.

Red Hat

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

Affected Software

14 affected componentsFixes available
redhat/atomic-openshift<0:3.11.542-1.git.0.f2fd300.el7
0:3.11.542-1.git.0.f2fd300.el7
redhat/openshift<0:4.3.37-202009120213.p0.git.0.dffefe4.el8
0:4.3.37-202009120213.p0.git.0.dffefe4.el8
redhat/openshift<0:4.4.0-202008250319.p0.git.0.d653415.el8
0:4.4.0-202008250319.p0.git.0.d653415.el8
redhat/openshift<0:4.5.0-202008130146.p0.git.0.aaf1d57.el8
0:4.5.0-202008130146.p0.git.0.aaf1d57.el8
redhat/kubernetes<1.19.0
1.19.0
redhat/kubernetes<1.18.6
1.18.6
redhat/kubernetes<1.17.10
1.17.10
redhat/kubernetes<1.16.13
1.16.13
go/k8s.io/kubernetes/pkg/kubelet>=1.18.0<1.18.6
1.18.6
go/k8s.io/kubernetes/pkg/kubelet>=1.17.0<1.17.9
1.17.9
go/k8s.io/kubernetes/pkg/kubelet>=1.1.0<1.16.13
1.16.13
Kubernetes kubernetes<1.16.13
Kubernetes kubernetes>=1.17.0<1.17.9
Kubernetes kubernetes>=1.18.0<1.18.6

Remediation

Information

On OpenShift Container Platform (OCP) 3.11 and 4.x it's possible to set the allowPrivilegeEscalation Security Context Constraint to 'false' to prevent this. Note that this is set to 'true' by default, and setting it to false will prevent certain binaries which require setuid to stop working. On OCP 3.11 for example the 'ping' command will no longer work [1]. On OCP 4.x and later the 'ping' command will work with allowPrivilegeEscalation set to False, but other setuid binaries will not work. [1] https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html

Event History

Jul 15, 2020
CVE Published
12:00 AM
Jul 23, 2020
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Apr 24, 2024
Advisory Published
via GitHub·08:01 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-8557?

CVE-2020-8557 is a vulnerability in Kubernetes that allows a pod to exceed the disk space limit for the /etc/hosts file.

2

Which versions of Kubernetes are affected by CVE-2020-8557?

Versions 1.1-1.16.12, 1.17.0-1.17.8, and 1.18.0-1.18.5 of Kubernetes are affected by CVE-2020-8557.

3

How does CVE-2020-8557 impact Kubernetes?

CVE-2020-8557 allows a pod in Kubernetes to write to its own /etc/hosts file and exceed the disk space limit, which is not accounted for by the kubelet eviction manager when calculating ephemeral storage.

4

What is the severity of CVE-2020-8557?

CVE-2020-8557 has a severity rating of medium with a CVSS score of 5.5.

5

How do I fix CVE-2020-8557 in Kubernetes?

To fix CVE-2020-8557 in Kubernetes, update to version 1.19.0, 1.18.6, or 1.17.10, depending on your current version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203