GPU VulnDB

Database/Container, Kubernetes & orchestration

Kyverno: a PolicyException meant to exempt one image disables image signature verification for the whole resource

CVSS 8.3CVE-2026-100704Container, Kubernetes & orchestrationcurated

Impact

The ImageValidatingPolicy evaluator in Kyverno 1.14.0 through 1.19.0 never reads spec.images or spec.allowedValues on a PolicyException. Any exception whose policyRefs and matchConditions match a resource turns off image signature verification for that entire resource instead of only the listed images, which is the opposite of how ValidatingPolicy, GeneratingPolicy and MutatingPolicy treat the same field. The practical result is that the narrow carve-out a platform team wrote for one trusted image silently admits every unsigned or untrusted image in the same pod spec - sidecars, init containers, a swapped model-server image. For a GPU fleet this is the admission gate that is supposed to keep unreviewed CUDA and inference images off the nodes, and it fails open without any error to notice. Exploitation is not required; a normal, correct-looking exception is enough.

Who can reach it

Any tenant or pipeline able to deploy workloads covered by an existing PolicyException, or able to create one, can ship unsigned images. Authenticated, namespace-level Kubernetes access; no cluster-admin needed.

What to do

Upgrade Kyverno to 1.19.1 or later and restart the admission controller. Before or alongside that, audit every PolicyException that references an ImageValidatingPolicy and narrow its matchConditions so the exemption covers only the intended resources, then review which images were actually admitted while an affected version ran - the gap leaves no distinct log entry, so treat unsigned images already running as unverified. Controller rollout only; no node work.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.