Description
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer dereference panic. As a consequence, the CSI Driver controller will be in denial of service. This bug has been fixed in Kubeedge 1.11.0, 1.10.1, and 1.9.3. Users should update to these versions to resolve the issue. At the time of writing, no workaround exists.
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/kubeedge/kubeedge/pull/3899/commits/5d60ae9eabd6b6b7afe38758e19bbe8137664701
Third Party Advisory x_refsource_confirm
https://github.com/kubeedge/kubeedge/security/advisories/GHSA-x938-fvfw-7jh5
Patch, Third Party Advisory x_refsource_misc
https://github.com/kubeedge/kubeedge/pull/3899
Scores
CVSS v3
4.0
EPSS
0.0034
EPSS Percentile
56.8%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (3)
kubeedge/kubeedge
1.10.0 - 1.10.1Go
linuxfoundation/kubeedge
1.10.0 (2 CPE variants)
linuxfoundation/kubeedge
< 1.9.3
Published
Jun 27, 2022
Tracked Since
Feb 18, 2026