Database/Container, Kubernetes & orchestration

gVisor: Reference-counting bug in mount-point tracking panics the sandbox
CVSS 4.8CVE-2023-7258Container, Kubernetes & orchestrationcurated
Impact
Reference-counting bug in mount-point tracking panics the sandbox
Who can reach it
A tenant running as root inside the sandbox with mount permission
What to do
Upgrade runsc; restart sandboxed pods
References
Related entries
- gVisor: runsc mishandles file access permissions, letting unprivileged users read restricted filesCVE-2025-2713 · gVisorMedium
- gVisor: Weak hashing and small seeds let a remote attacker derive a local IP and per-boot identifierCVE-2024-10026 · gVisorMedium
- gVisor: Predictable TCP/UDP source ports and header values enable off-path attacksCVE-2024-10603 · gVisorMedium
- ingress-nginx: auth-secret file path traversal in the controllerCVE-2025-24513 · ingress-nginxMedium
- Traefik: Cross-namespace isolation not enforced in the Kubernetes CRD providerCVE-2026-41174 · TraefikMedium
- Traefik: cross-namespace TraefikService references are not rejected, defeating allowCrossNamespace=false isolationCVE-2026-71325 · Traefik Kubernetes CRD provider (TraefikService backend reference resolution)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.