CVE-2019-14891
published 2019-11-25CVE-2019-14891: A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon)…
PriorityP427medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
EPSS
0.69%
49.1th percentile
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kubernetes | cri-o | < 1.16.1 | 1.16.1 |
| kubernetes | cri-o | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv3.05.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cri-o: infra container reparented to systemd following OOM Killer killing it's conmon
vendor_redhat·2019-11-07·CVSS 5.0
CVE-2019-14891 [MEDIUM] CWE-460 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon
cri-o: infra container reparented to systemd following OOM Killer killing it's conmon
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
Mitigation: As of cri-o v1.15 you
GHSA
GHSA-7hwv-gxwq-2g5p: A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup
ghsa_unreviewed·2022-05-24
CVE-2019-14891 [MEDIUM] CWE-460 GHSA-7hwv-gxwq-2g5p: A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon [fedora-all]
bugzilla·2019-11-19·CVSS 5.0
CVE-2019-14891 [MEDIUM] CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon [fedora-all]
CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon
bugzilla·2019-11-14·CVSS 5.0
CVE-2019-14891 [MEDIUM] CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon
CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon
Cri-o pods didn't provide sufficient isolation between the workload and infra containers such that when a workload consumed a large amount of memory, the kernel accidently killed the infra container's conmon process. An attacker would use the flaw to get host network access on an Kubernetes worker node.
Discussion:
Acknowledgments:
Name: Nick Freeman (Capsule8)
---
Created cri-o tracking bugs for this issue:
Affects: fedora-all [bug 1774273]
---
Mitigation:
As of cri-o v1.15 you can set conmon_cgroup = "system.slice" in the crio.runtime section of /etc/crio/crio.conf. On OpenShift Container Platform 4.x that can be done by following the documentation here:
https://access.redhat.co
2019-11-25
Published