Database/Container, Kubernetes & orchestration
KubeEdge CloudHub: unvalidated 32-bit payload length lets an edge peer exhaust control-plane memory
Impact
Reader.Read in pkg/viaduct/pkg/packer allocates whatever the 32-bit PackageHeader.PayloadLen claims before checking an upper bound. A connected edge node that is malicious or compromised can send crafted headers repeatedly until CloudHub exhausts memory and dies or enters a restart loop, cutting cloud-edge communication for every node until it stabilizes. Where accelerator nodes are enrolled as KubeEdge edge nodes, that is loss of scheduling and status reporting for the fleet, and the blast radius is the whole control-plane component rather than the one misbehaving node. No unauthenticated access and no code execution.
Who can reach it
An authenticated edge peer - a node already enrolled in the cluster, or an attacker holding its credentials - talking to CloudHub over the viaduct channel. Not reachable without valid edge credentials.
What to do
Upgrade KubeEdge to 1.21.2, 1.22.2 or 1.23.1 and restart CloudHub; this is a control-plane deployment rollout, not a node reboot, though edge nodes will briefly lose their cloud connection during the restart. Affected from 1.0.0 onward.
References
Related entries
- Submariner: IPsec pre-shared key stored unencrypted in the Submariner custom resourceCVE-2026-66781 · Submariner operator (Submariner CR, IPsec pre-shared key)Medium
- KubeSphere cluster-controller: Cluster CRD endpoint is fetched unvalidated, giving SSRF from the controller podCVE-2026-71208 · KubeSphere cluster-controller (Cluster CRD connection config, addCluster / Discovery.ServerVersion)Medium
- ECK operator: unvalidated secret reference lets a namespace-scoped user read secrets from any namespaceCVE-2026-72640 · Elastic Cloud on Kubernetes (ECK) operator (secret reference reconciliation)Medium
- Elastic Cloud on Kubernetes: Fleet Server Elasticsearch token written into the workload spec in cleartextCVE-2026-72648 · Elastic Cloud on Kubernetes (ECK) operator - Fleet Server workload specMedium
- Dokploy: compose service names are interpolated into shell commands, giving command execution on the Docker hostCVE-2026-72739 · Dokploy (compose deployment createCommand shell interpolation)Medium
- Rancher Fleet: bundle content can read files from the bundle-processing job and leak Helm registry credentialsCVE-2026-93537 · SUSE Rancher Fleet (GitRepo bundle processing, file read into Bundle resource)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.