GPU VulnDB

Database/Container, Kubernetes & orchestration

Crossplane runtime: time-of-check/time-of-use in xpkg ImageConfig resolution

CVSS 6.9CVE-2026-105163Container, Kubernetes & orchestrationcurated

Impact

The ImageConfig Get path in pkg/xpkg/client.go checks and then uses image configuration in separate steps, so the configuration in force when a package image is fetched can differ from the one that was validated. The practical consequence per the record is a limited integrity effect - the registry/pull settings applied to a package can diverge from the ones policy approved - with no stated confidentiality or availability impact. For an operator running Crossplane as the control plane that provisions GPU clusters, storage and network, the concern is that package installation can proceed under configuration that was not the one evaluated, weakening a trust boundary the platform team relies on. The record gives no exploit detail beyond the TOCTOU classification, so do not read this as package-content substitution without further vendor detail.

Who can reach it

Remote per the CVSS vector, no authentication stated, against the Crossplane control plane's package-installation path. In practice the reachable surface is whoever can influence package or ImageConfig resources, or the registry responses behind them.

What to do

Upgrade crossplane-runtime to 2.2.3 or 2.3.3 (or 2.4.0-rc.1) - in practice, bump the Crossplane core and provider images that vendor it and let the deployment roll. Only the control-plane pods restart; GPU worker nodes are untouched and no drain or reboot is required. The fix is commit bee99c6cd6ca81878acca2940a2f0a02169fc208.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.