Bug 1554531
| Summary: | Docker daemon panics with "out of memory" when large docker cp executed | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Clayton Coleman <ccoleman> |
| Component: | Containers | Assignee: | Antonio Murdaca <amurdaca> |
| Status: | CLOSED DUPLICATE | QA Contact: | DeShuai Ma <dma> |
| Severity: | high | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 3.9.0 | CC: | aos-bugs, jhonce, jlebon, jokerman, mmccomas |
| Target Milestone: | --- | ||
| Target Release: | 3.9.0 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-03-13 17:31:51 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Clayton Coleman
2018-03-12 21:50:53 UTC
This does not seem to be happening in 1.12, or at least I have not seen it before. Holding the entire contents of request or response in memory is an attack vector for anything shared like the docker daemon. If we have anything reading everything it needs to only be done for requests below a certain size, otherwise this could be used to DoS the shared daemon. This is probably a dupe of https://bugzilla.redhat.com/show_bug.cgi?id=1489517. See also the Fedora version, https://bugzilla.redhat.com/show_bug.cgi?id=1489505, which has some more updates. *** This bug has been marked as a duplicate of bug 1489517 *** |