Database/Container, Kubernetes & orchestration
Crossplane runtime: time-of-check/time-of-use in xpkg ImageConfig resolution
Impact
The ImageConfig Get path in pkg/xpkg/client.go checks and then uses image configuration in separate steps, so the configuration in force when a package image is fetched can differ from the one that was validated. The practical consequence per the record is a limited integrity effect - the registry/pull settings applied to a package can diverge from the ones policy approved - with no stated confidentiality or availability impact. For an operator running Crossplane as the control plane that provisions GPU clusters, storage and network, the concern is that package installation can proceed under configuration that was not the one evaluated, weakening a trust boundary the platform team relies on. The record gives no exploit detail beyond the TOCTOU classification, so do not read this as package-content substitution without further vendor detail.
Who can reach it
Remote per the CVSS vector, no authentication stated, against the Crossplane control plane's package-installation path. In practice the reachable surface is whoever can influence package or ImageConfig resources, or the registry responses behind them.
What to do
Upgrade crossplane-runtime to 2.2.3 or 2.3.3 (or 2.4.0-rc.1) - in practice, bump the Crossplane core and provider images that vendor it and let the deployment roll. Only the control-plane pods restart; GPU worker nodes are untouched and no drain or reboot is required. The fix is commit bee99c6cd6ca81878acca2940a2f0a02169fc208.
References
Related entries
- BuildKit: Crafted upload request lets files escape the BuildKit state directory onto the hostCVE-2026-15789 · BuildKitMedium
- Istio: Envoy RBAC header matching flaw bypasses header-based authorization policyCVE-2026-31838 · IstioMedium
- containerd: crafted OCI image index exhausts node CPU and memory during image pullCVE-2026-53493 · containerd (OCI index graph handling in PullImage)Medium
- Kyverno: unvalidated ServiceCall URL turns the cluster-wide ServiceAccount into a confused deputyCVE-2026-84199 · Kyverno admission controller (APICall ServiceCall URL field)Medium
- NGINX: HTTP/3 handshake can overflow a heap buffer in the worker, restarting it or corrupting dataCVE-2026-90439 · NGINX ngx_http_v3_module (HTTP/3 TLS handshake with OpenSSL <= 3.5.0)Medium
- Istio: DENY AuthorizationPolicy with wildcard-suffix principals silently fails to denyCVE-2020-16844 · IstioMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.