Database/Container, Kubernetes & orchestration

gVisor: Weak hashing and small seeds let a remote attacker derive a local IP and per-boot identifier
CVSS 6.3CVE-2024-10026Container, Kubernetes & orchestrationcurated
Impact
Weak hashing and small seeds let a remote attacker derive a local IP and per-boot identifier; sandbox fingerprinting
Who can reach it
Unauthenticated network
What to do
Upgrade runsc
References
Related entries
- gVisor: Predictable TCP/UDP source ports and header values enable off-path attacksCVE-2024-10603 · gVisorMedium
- gVisor: Reference-counting bug in mount-point tracking panics the sandboxCVE-2023-7258 · gVisorMedium
- gVisor: runsc mishandles file access permissions, letting unprivileged users read restricted filesCVE-2025-2713 · gVisorMedium
- Argo Workflows (Argo Server, archived workflow retrieval under client/sso auth mode): With --auth-mode=client theCVE-2024-53862 · Argo Workflows (Argo Server, archived workflow retrieval under client/sso auth mode)Medium
- Kubernetes Image Builder: Default credentials present during the build window for several providersCVE-2024-9594 · Kubernetes Image BuilderMedium
- containerd: Unbounded read on OCI image import causes containerd OOMCVE-2023-25153 · containerdMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.