Bug 1772727 (CVE-2019-11255)

Summary: CVE-2019-11255 kubernetes-csi: CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
Product: [Other] Security Response Reporter: Sam Fowler <sfowler>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aos-bugs, aos-storage-staff, bmontgom, eparis, jburrell, jokerman, jsafrane, nstielau, sponnaga
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-12-11 07:24:01 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1774304, 1774305, 1774306, 1774307, 1774310, 1779024    
Bug Blocks: 1772728    

Description Sam Fowler 2019-11-15 01:33:58 UTC
A security issue has been found in the kubernetes-csi external-provisioner, external-snapshotter, and external-resizer sidecars that impacts most versions of the sidecars bundled in Container Storage Interface (CSI) drivers. The vulnerabilities are medium severity and can result in unauthorized volume data access or mutation when using CSI volume snapshot, cloning or resizing features in Kubernetes. Upgrading your CSI drivers to the fixed sidecars is recommended.


Upstream Issue:

https://github.com/kubernetes/kubernetes/issues/85233


External Reference:

https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw

Comment 3 Sam Fowler 2019-11-20 05:32:56 UTC
Statement:

OpenShift Container Storage Interface (CSI) is a Technology Preview (TP) feature in OpenShift Container Platform before version 4.2.

https://access.redhat.com/support/offerings/techpreview

Comment 7 errata-xmlrpc 2019-12-11 04:54:19 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.2

Via RHSA-2019:4099 https://access.redhat.com/errata/RHSA-2019:4099

Comment 8 Product Security DevOps Team 2019-12-11 07:24:01 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-11255

Comment 9 errata-xmlrpc 2019-12-11 08:39:12 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.2

Via RHSA-2019:4096 https://access.redhat.com/errata/RHSA-2019:4096

Comment 11 errata-xmlrpc 2019-12-16 13:55:50 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 3.11

Via RHSA-2019:4054 https://access.redhat.com/errata/RHSA-2019:4054

Comment 12 errata-xmlrpc 2019-12-17 02:18:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.1

Via RHSA-2019:4225 https://access.redhat.com/errata/RHSA-2019:4225