Database/Container, Kubernetes & orchestration
Kubernetes (in-tree storage): Crafted PV/pod on Windows nodes escalates to node admin via in-tree storage plugin
CVSS 7.2CVE-2023-5528Container, Kubernetes & orchestrationcurated
Impact
Crafted PV/pod on Windows nodes escalates to node admin via in-tree storage plugin
Who can reach it
Cluster user able to create pods and PVs
What to do
Rolling control-plane and kubelet upgrade; Windows node drain
References
Related entries
- Cilium: HTTP policies not consistently applied to all trafficCVE-2024-28248 · CiliumHigh
- CRI-O: arbitrary systemd property injection via a pod annotation gives action on the hostCVE-2024-3154 · CRI-O container runtime (pod annotation to systemd property injection)High
- Docker Engine: docker cp of a compressed archive runs the container's own xz/unpigz with daemon privilegesCVE-2026-41567 · Docker Engine / moby daemon (docker cp archive decompression)High
- Docker / moby: Race condition during `docker cp` mount setup allows escape/host accessCVE-2026-42306 · Docker / mobyHigh
- BuildKit: crafted upload request writes files outside the daemon-controlled state directoryCVE-2026-75593 · BuildKit daemon (build context upload / state directory)High
- Cilium (VLAN interface datapath, TCX attachment): Ingress host policies and L7 network policies silently stop beingNCVD-2026-047-cilium-vlan-interface-datapath-t · Cilium (VLAN interface datapath, TCX attachment)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.