GPU VulnDB

Database/Container, Kubernetes & orchestration

kube-compare: a container:// reference runs the untrusted image entrypoint instead of extracting from it

CVSS 7.1CVE-2026-87114Container, Kubernetes & orchestrationcurated

Impact

kube-compare is the OpenShift cluster-configuration comparison tool cluster operators run against live clusters. When given a 'container://' reference path it executes the referenced image's entrypoint rather than only extracting data from a stopped container, so a reference chosen by an attacker runs code on the machine the operator is working from. Because that machine is typically the one holding kubeconfigs and cluster-admin credentials for the GPU clusters, the blast radius is the credentials, not the workstation. Where the Docker daemon runs with elevated privileges the untrusted code inherits root-mediated daemon privileges. Exploitation needs the operator to act on an attacker-supplied reference, which is what holds the score to 7.1.

Who can reach it

A local execution path requiring user interaction: a cluster operator runs kube-compare against a reference metadata set or 'container://' path supplied or influenced by someone else. No prior authentication to the tool is needed - the trust boundary is the reference the operator chooses to pass in.

What to do

Follow the Red Hat advisory for the fixed kube-compare build and update the plugin on every operator workstation and bastion - a client-side binary replacement, no cluster or node maintenance window. Until updated, do not pass 'container://' references from sources you do not control, and avoid running the tool on a host whose Docker daemon has elevated privileges. The advisory text available here does not name a fixed version.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.