Database/Container, Kubernetes & orchestration
Intel Device Plugins for Kubernetes (GPU/accelerator device plugin, access control): Improper access control in Intel's
Impact
Improper access control in Intel's Kubernetes device plugins lets a privileged local user deny service on the node. Because the device plugin is what advertises and allocates accelerators to the kubelet, knocking it over means the node stops offering its accelerators and scheduled workloads lose their allocation.
Who can reach it
A privileged user with local access to a node running Intel Device Plugins for Kubernetes before 0.32.0.
What to do
Upgrade the Intel device plugin DaemonSet to 0.32.0 or later and let it roll across the nodes. The DaemonSet restart is enough - no drain or reboot - but confirm accelerator capacity re-registers on each node after the rollout.
References
Related entries
- Harbor: SSRF: a user who can edit projects scans the Harbor host's intranetCVE-2020-13788 · HarborMedium
- Kubernetes (kubelet): Kubelet API DoS, including via the unauthenticated read-only portCVE-2020-8551 · Kubernetes (kubelet)Medium
- Argo CD: Unauthenticated attackers can enumerate existing applicationsCVE-2022-41354 · Argo CDMedium
- cosign / sigstore: verify-blob-attestation reports "Verified OK" for malformed or mismatched payloadsCVE-2026-39395 · cosign / sigstoreMedium
- Kite dashboard: any authenticated user can read cluster overview data for clusters they cannot accessCVE-2026-53487 · Kite Kubernetes dashboard (/api/v1/overview cluster authorization bypass)Medium
- Skipper: unbounded admission request body read lets a client OOM the proxy processCVE-2026-54247 · Skipper Kubernetes admission webhook (:9443/admission request body)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.