Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in kubernetes. On Windows nodes, kubelet evaluates symbolic links when preparing a pod volume subPath. That check is supposed to refuse device and UNC targets so Windows does not open a network path while resolving the link. The implementation only matches extended device prefixes (\\?\, \\.) and the stripped UNC form, so an ordinary UNC target such as \\server\share is treated as a local path and followed. If an attacker can create a pod that is scheduled onto a Windows node and whose volume subPath is a symbolic link to an attacker-controlled SMB share, kubelet follows the link. Windows then starts an SMB session and sends the NetNTLMv2 hash of the account under which kubelet is running (typically the node computer account when the node is domain-joined). The attacker can try to crack that hash or, with additional NTLM-relay conditions, impersonate the node. This code is Windows-only (pkg/volume/util/subpath/subpath_windows.go). Linux kubelet is not built with it. In Red Hat OpenShift, the Windows kubelet is the kubelet.exe that Windows Machine Config Operator (WMCO) installs on Windows workers, not the Linux kubelet on RHCOS nodes. Clusters with no Windows nodes are not affected.