-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability root cause was the kubelet's failure to include pod /etc/hosts file in ephemeral storage calculations. The patch adds explicit handling for this file in podLocalEphemeralStorageUsage. The pre-patch version of this function lacked the critical 'os.Stat(etcHostsPath)' check and subsequent disk usage accounting shown in the diff, making it the clear vulnerable function. The eviction manager's modifications to pass etcHostsPath parameter and call pattern changes confirm this was the missing piece in storage calculation logic.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| k8s.io/kubernetes/pkg/kubelet | go | >= 1.1.0, < 1.16.13 | 1.16.13 |
| k8s.io/kubernetes/pkg/kubelet | go | >= 1.17.0, < 1.17.9 | 1.17.9 |
| k8s.io/kubernetes/pkg/kubelet | go | >= 1.18.0, < 1.18.6 | 1.18.6 |
Ongoing coverage of React2Shell