Bug 2507531 (CVE-2026-66786) - CVE-2026-66786 submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets
Summary: CVE-2026-66786 submariner: submariner: ipsec.conf stanza injection via remote...
Keywords:
Status: NEW
Alias: CVE-2026-66786
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-27 15:44 UTC by OSIDB Bzimport
Modified: 2026-08-21 17:00 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-27 15:44:40 UTC
In cert-auth mode the connection stanza is built with fmt.Sprintf and written to submariner.conf. Spec.CableName and Spec.Subnets are free-form strings in the CRD with no pattern validation. A malicious cluster can publish a CableName containing newlines and ipsec.conf directives (e.g. authby=never, rightsubnet=0.0.0.0/0, leftupdown=/bin/sh) to inject arbitrary stanza parameters or execute commands via leftupdown hooks. This enables remote code execution as root on the gateway node.

Source: Project Glasswing AI-SAST audit of submariner-io/submariner.
Finding ID: FIND-005
Assurance: machine_verified


Note You need to log in before you can comment on or make changes to this bug.