Database/Container, Kubernetes & orchestration

gVisor: Predictable TCP/UDP source ports and header values enable off-path attacks
CVSS 6.3CVE-2024-10603Container, Kubernetes & orchestrationcurated
Impact
Predictable TCP/UDP source ports and header values enable off-path attacks
Who can reach it
Unauthenticated network
What to do
Upgrade runsc
References
Related entries
- gVisor: Reference-counting bug in mount-point tracking panics the sandboxCVE-2023-7258 · gVisorMedium
- gVisor: runsc mishandles file access permissions, letting unprivileged users read restricted filesCVE-2025-2713 · gVisorMedium
- gVisor: Weak hashing and small seeds let a remote attacker derive a local IP and per-boot identifierCVE-2024-10026 · gVisorMedium
- Argo Workflows (Argo Server, archived workflow retrieval under client/sso auth mode): With --auth-mode=client theCVE-2024-53862 · Argo Workflows (Argo Server, archived workflow retrieval under client/sso auth mode)Medium
- Kubernetes Image Builder: Default credentials present during the build window for several providersCVE-2024-9594 · Kubernetes Image BuilderMedium
- containerd: Unbounded read on OCI image import causes containerd OOMCVE-2023-25153 · containerdMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.