Executive brief
Early versions of the Operator-SDK, a tool used to build Kubernetes applications, contain a security flaw that sets incorrect permissions on sensitive system files within container images. This allows an attacker who has already gained limited access to a container to escalate their privileges to full administrative (root) control. Such an exploit could allow an attacker to bypass security boundaries, access sensitive data, or disrupt operations within the containerized environment.
Technical details
The vulnerability stems from the 'user_setup' script in Operator-SDK (versions prior to 0.15.2), which modifies the permissions of /etc/passwd to 664 (world-readable, group-writable) during the container build process. Because the file is owned by the root group (GID 0), any user belonging to the root group—even if they are not the root user—can modify the file. An attacker with local command execution can exploit this to append a new user entry with UID 0 to /etc/passwd, effectively gaining full root privileges within the container. This issue persists in any container images scaffolded with the vulnerable SDK versions if the legacy script is still utilized. Red Hat has released updated images for various products to mitigate this risk.
Affected products
- operator-framework operator-sdk < 0.15.2
- Red Hat RHEL-9-CNV-4.17 < v4.17.39-2
- Red Hat RHEL-9-CNV-4.18 < v4.18.25-3
- Red Hat RHEL-9-CNV-4.20 < v4.20.3-3
Timeline
- 2025-08-07: disclosed: CVE published to NVD
- 2025-12-16: patched: Red Hat released updated images for OpenShift Virtualization 4.20.3
References
- https://github.com/operator-framework/operator-sdk
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHEA-2025:23406
- https://access.redhat.com/errata/RHEA-2025:23478
- https://access.redhat.com/errata/RHEA-2026:0129
- https://access.redhat.com/errata/RHSA-2025:19332