PT-2020-20207 · Kubernetes+1 · Kubernetes+1

Kebe Liu

·

Published

2020-07-15

·

Updated

2025-08-08

·

CVE-2020-8557

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kubernetes versions 1.1 through 1.16.12 Kubernetes versions 1.17.0 through 1.17.8 Kubernetes versions 1.18.0 through 1.18.5
Description The issue concerns the kubelet component of Kubernetes, where it fails to account for disk usage by a pod that writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included in the calculation of ephemeral storage usage by the kubelet eviction manager. This could lead to a pod filling the node's storage space and causing the node to fail.
Recommendations For Kubernetes versions 1.1 through 1.16.12, consider restricting access to the /etc/hosts file to prevent excessive writing. For Kubernetes versions 1.17.0 through 1.17.8, consider implementing a workaround to monitor and limit disk usage by pods. For Kubernetes versions 1.18.0 through 1.18.5, consider disabling the writing of large amounts of data to the /etc/hosts file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2454
ALT-PU-2020-2462
CVE-2020-8557
GHSA-55QJ-GJ3X-JQ9R
GO-2024-2753
OPENSUSE-SU-2025:15424-1
RHSA-2020:3519
RHSA-2020:3579
RHSA-2020:3808
RHSA-2021:3915
SUSE-RU-2020:2204-1

Affected Products

Alt Linux
Kubernetes