Database/Container, Kubernetes & orchestration
kube-compare: a container:// reference runs the untrusted image entrypoint instead of extracting from it
Impact
kube-compare is the OpenShift cluster-configuration comparison tool cluster operators run against live clusters. When given a 'container://' reference path it executes the referenced image's entrypoint rather than only extracting data from a stopped container, so a reference chosen by an attacker runs code on the machine the operator is working from. Because that machine is typically the one holding kubeconfigs and cluster-admin credentials for the GPU clusters, the blast radius is the credentials, not the workstation. Where the Docker daemon runs with elevated privileges the untrusted code inherits root-mediated daemon privileges. Exploitation needs the operator to act on an attacker-supplied reference, which is what holds the score to 7.1.
Who can reach it
A local execution path requiring user interaction: a cluster operator runs kube-compare against a reference metadata set or 'container://' path supplied or influenced by someone else. No prior authentication to the tool is needed - the trust boundary is the reference the operator chooses to pass in.
What to do
Follow the Red Hat advisory for the fixed kube-compare build and update the plugin on every operator workstation and bastion - a client-side binary replacement, no cluster or node maintenance window. Until updated, do not pass 'container://' references from sources you do not control, and avoid running the tool on a host whose Docker daemon has elevated privileges. The advisory text available here does not name a fixed version.
References
Related entries
- Consul Connect: unescaped service names generate over-broad Envoy RBAC rules, bypassing intentionsCVE-2026-88021 · HashiCorp Consul Connect service mesh (Envoy RBAC rule generation)High
- Harbor: fuzzy q filter on scanner credentials lets a project admin extract the adapter secret character by characterCVE-2026-92770 · Harbor registry (scanner registration AccessCredential, q query parameter)High
- runc: Volume-mount race gives incorrect access control and privilege escalation to hostCVE-2019-19921 · runcHigh
- Podman: File permissions not checked for non-root users in a privileged containerCVE-2021-20188 · PodmanHigh
- runc: Regression of CVE-2019-19921: incorrect access control leading to privilege escalation via volume mountsCVE-2023-27561 · runcHigh
- Slurm: Filesystem race conditions allow gaining ownership of, overwriting, or deleting filesCVE-2023-41914 · SlurmHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.