Database/Container, Kubernetes & orchestration
Argo Workflows (controller, daemon workflow SPDY client race): A data race in a global variable in the Kubernetes SPDY
Impact
A data race in a global variable in the Kubernetes SPDY client path lets any user who can run a workflow panic the workflow controller on demand. One tenant issuing back-to-back daemon workflows halts scheduling for every other tenant sharing that controller.
Who can reach it
Any principal with permission to execute a workflow in a namespace the controller watches. No elevated rights needed.
What to do
Upgrade the controller off 3.6.0-rc1 to 3.6.0-rc2 or any later release and restart. If you are running a release candidate in production, this is the signal to move to a GA build.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.