CVE-2020-8557: Kubernetes node disk Denial of Service by writing to container /etc/hosts

Published May 14, 2020
·
Updated

A flaw was found in Kubernetes, where the amount of disk space the /etc/hosts file can use is unconstrained . This flaw can allow attacker-controlled pods to cause a denial of service if they have permission to write to the node's /etc/hosts file.

Other sources

The kubelet sets up a file called etc-hosts for each pod, which is mounted in the containers as /etc/hosts. The file isn't counted against memory limits (as a tmpfs file would be) or ephemeral storage usage limits. The container can fill up the node disk on the node which it was scheduled.

Red Hat

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

Affected Software

15 affected componentsFixes available
redhat/atomic-openshift<0:3.11.542-1.git.0.f2fd300.el7
0:3.11.542-1.git.0.f2fd300.el7
redhat/openshift<0:4.3.37-202009120213.p0.git.0.dffefe4.el8
0:4.3.37-202009120213.p0.git.0.dffefe4.el8
redhat/openshift<0:4.4.0-202008250319.p0.git.0.d653415.el8
0:4.4.0-202008250319.p0.git.0.d653415.el8
redhat/openshift<0:4.5.0-202008130146.p0.git.0.aaf1d57.el8
0:4.5.0-202008130146.p0.git.0.aaf1d57.el8
redhat/kubernetes<1.19.0
1.19.0
redhat/kubernetes<1.18.6
1.18.6
redhat/kubernetes<1.17.10
1.17.10
redhat/kubernetes<1.16.13
1.16.13
go/k8s.io/kubernetes/pkg/kubelet>=1.18.0<1.18.6
1.18.6
go/k8s.io/kubernetes/pkg/kubelet>=1.17.0<1.17.9
1.17.9
go/k8s.io/kubernetes/pkg/kubelet>=1.1.0<1.16.13
1.16.13
Kubernetes kubernetes<1.16.13
Kubernetes kubernetes>=1.17.0<1.17.9
Kubernetes kubernetes>=1.18.0<1.18.6
IBM Netezza Software<=11.3.0.3-IF2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/atomic-openshift to a version that resolves this vulnerability.

    Fixed in 0:3.11.542-1.git.0.f2fd300.el7
  2. Upgrade

    Upgrade redhat/openshift to a version that resolves this vulnerability.

    Fixed in 0:4.3.37-202009120213.p0.git.0.dffefe4.el8
  3. Upgrade

    Upgrade redhat/openshift to a version that resolves this vulnerability.

    Fixed in 0:4.4.0-202008250319.p0.git.0.d653415.el8
  4. Upgrade

    Upgrade redhat/openshift to a version that resolves this vulnerability.

    Fixed in 0:4.5.0-202008130146.p0.git.0.aaf1d57.el8
  5. Upgrade

    Upgrade redhat/kubernetes to a version that resolves this vulnerability.

    Fixed in 1.19.0
  6. Upgrade

    Upgrade redhat/kubernetes to a version that resolves this vulnerability.

    Fixed in 1.18.6
  7. Upgrade

    Upgrade redhat/kubernetes to a version that resolves this vulnerability.

    Fixed in 1.17.10
  8. Upgrade

    Upgrade redhat/kubernetes to a version that resolves this vulnerability.

    Fixed in 1.16.13
  9. Upgrade

    Upgrade go/k8s.io/kubernetes/pkg/kubelet to a version that resolves this vulnerability.

    Fixed in 1.18.6
  10. Upgrade

    Upgrade go/k8s.io/kubernetes/pkg/kubelet to a version that resolves this vulnerability.

    Fixed in 1.17.9
  11. Upgrade

    Upgrade go/k8s.io/kubernetes/pkg/kubelet to a version that resolves this vulnerability.

    Fixed in 1.16.13
  12. Configuration

    Set the allowPrivilegeEscalation Security Context Constraint to 'false' to prevent pods/binaries that require setuid from operating (noting on OCP 3.11 the 'ping' command will no longer work, and on OCP 4.x and later 'ping' will work with allowPrivilegeEscalation set to False but other setuid binaries will not).

    Kubernetes (OpenShift Security Context Constraints) allowPrivilegeEscalation allowPrivilegeEscalation = false
  13. Compensating control

    Apply a compensating control by restricting which pods are allowed to write to/affect the node's /etc/hosts file (e.g., prevent attacker-controlled pods from having permissions that allow this behavior) to mitigate node disk DoS via oversized /etc/hosts writes.

Event History

Jul 15, 2020
CVE Published
12:00 AM
Jul 23, 2020
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Apr 24, 2024
Advisory Published
via GitHub·08:01 PM
Aug 20, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is CVE-2020-8557?

CVE-2020-8557 is a vulnerability in Kubernetes that allows a pod to exceed the disk space limit for the /etc/hosts file.

2

Which versions of Kubernetes are affected by CVE-2020-8557?

Versions 1.1-1.16.12, 1.17.0-1.17.8, and 1.18.0-1.18.5 of Kubernetes are affected by CVE-2020-8557.

3

How does CVE-2020-8557 impact Kubernetes?

CVE-2020-8557 allows a pod in Kubernetes to write to its own /etc/hosts file and exceed the disk space limit, which is not accounted for by the kubelet eviction manager when calculating ephemeral storage.

4

What is the severity of CVE-2020-8557?

CVE-2020-8557 has a severity rating of medium with a CVSS score of 5.5.

5

How do I fix CVE-2020-8557 in Kubernetes?

To fix CVE-2020-8557 in Kubernetes, update to version 1.19.0, 1.18.6, or 1.17.10, depending on your current version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203