Executive brief
A security flaw was found in certain Red Hat Multicluster Engine for Kubernetes container images. This vulnerability allows a user who already has limited access to a container to gain full administrative (root) control over that container. This could lead to unauthorized access to sensitive data or the ability to disrupt services running within the affected container environment.
Technical details
A privilege escalation vulnerability exists in Red Hat Multicluster Engine for Kubernetes images due to incorrect default permissions (CWE-276). The /etc/passwd file is created with group-writable permissions during the image build process. An attacker who can execute commands within the container and is a member of the root group can modify /etc/passwd to add a new user with UID 0. This allows the attacker to escalate from a non-root user to full root privileges within the container environment. The attack requires local access and high privileges (membership in the root group) to succeed.
Affected products
- Red Hat Multicluster Engine for Kubernetes unspecified
Timeline
- 2025-08-26: disclosed: Initial report in Red Hat Bugzilla
- 2026-04-08: advisory: NVD publication date