GPU VulnDB

Database/Container, Kubernetes & orchestration

KubeEdge CloudHub: unvalidated 32-bit payload length lets an edge peer exhaust control-plane memory

CVSS 6.5CVE-2026-62370Container, Kubernetes & orchestrationcurated

Impact

Reader.Read in pkg/viaduct/pkg/packer allocates whatever the 32-bit PackageHeader.PayloadLen claims before checking an upper bound. A connected edge node that is malicious or compromised can send crafted headers repeatedly until CloudHub exhausts memory and dies or enters a restart loop, cutting cloud-edge communication for every node until it stabilizes. Where accelerator nodes are enrolled as KubeEdge edge nodes, that is loss of scheduling and status reporting for the fleet, and the blast radius is the whole control-plane component rather than the one misbehaving node. No unauthenticated access and no code execution.

Who can reach it

An authenticated edge peer - a node already enrolled in the cluster, or an attacker holding its credentials - talking to CloudHub over the viaduct channel. Not reachable without valid edge credentials.

What to do

Upgrade KubeEdge to 1.21.2, 1.22.2 or 1.23.1 and restart CloudHub; this is a control-plane deployment rollout, not a node reboot, though edge nodes will briefly lose their cloud connection during the restart. Affected from 1.0.0 onward.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.