Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN941 _____________________________________________________________________ DATE : 28/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running kube-controller-manager versions prior to 1.34.12, 1.35.9, 1.36.5, 1.37.1, kubelet versions prior to 1.34.12, 1.35.9, 1.36.5, 1.37.1. ===================================================================== https://groups.google.com/g/kubernetes-announce/c/gI9iatwmRbA https://groups.google.com/g/kubernetes-announce/c/ZN4CNe2li2w _____________________________________________________________________ [Security Advisory] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation Nathan Herz à kubernete...@googlegroups.com,d...@kubernetes.io, kubernetes-sec...@googlegroups.com,kubernetes-se...@googlegroups.com, distributo...@kubernetes.io Hello Kubernetes Community, A confused deputy attack exists in the StatefulSet controller that allows a user with namespace-scoped write permissions on StatefulSet and ControllerRevision objects to create a cross-namespace pod. An attacker exploiting this vulnerability would have full control over the resulting pod’s metadata and specification, including namespace selection. Note that the cross-namespace pod will be immediately deleted by the garbage collector unless the attacker is able to construct a valid StatefulSet OwnerReference. This would require referencing the UID of an existing StatefulSet in the victim’s namespace. This issue has been rated Medium (5.9) CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N, and assigned CVE-2026-2270. Affected Versions kube-controller-manager: <= v1.34.11 kube-controller-manager: <= v1.35.8 kube-controller-manager: <= v1.36.4 kube-controller-manager: = v1.37.0 How do I mitigate this vulnerability? This issue can be mitigated by upgrading to a fixed kube-controller-manager version. The fixed versions are patched to ensure that only the spec field in StatefulSets will be restored from ControllerRevisions. Fixed Versions kube-controller-manager: >= v1.34.12 kube-controller-manager: >= v1.35.9 kube-controller-manager: >= v1.36.5 kube-controller-manager: >= v1.37.1 If you find evidence that this vulnerability has been exploited, please contact secu...@kubernetes.io. Additional Details See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/142097 Acknowledgements This vulnerability was reported by ImanOracle. The issue was fixed and coordinated by: Maciej Szulik @soltysh Filip Křepinský @atiratree Verónica López @Verolop Jeremy Rickard @jeremyrickard Nathan Herz @natherz97 Thank you, Nathan Herz on behalf of the Kubernetes Security Response Committee _____________________________________________________________________ [Security Advisory] CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion Nathan Herz à kubernete...@googlegroups.com,d...@kubernetes.io, kubernetes-sec...@googlegroups.com,kubernetes-se...@googlegroups.com, distributo...@kubernetes.io Hello Kubernetes Community, An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symbolic link that points to an attacker-controlled network share. When a kubelet resolves symlinks, it does not reject a target that resolves to a UNC path. As a result, the kubelet will transparently attempt to authenticate to the share using NTLM. This allows an attacker to obtain the NetNTLMv2 hash of the account under which the kubelet is running. An attacker could then attempt to crack the hash to retrieve the corresponding password or relay it to impersonate the node, if the node is domain-joined. This issue has been rated Medium (5.8) CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N, and assigned CVE-2026-76654. Affected Versions kubelet: <= v1.34.11 kubelet: <= v1.35.8 kubelet: <= v1.36.4 kubelet: = v1.37.0 How do I mitigate this vulnerability? This issue can be mitigated by upgrading to a fixed kubelet version. The fixed versions update kubelet to refuse UNC symlink targets on Windows. Fixed Versions kubelet: >= v1.34.12 kubelet: >= v1.35.9 kubelet: >= v1.36.5 kubelet: >= v1.37.1 If you find evidence that this vulnerability has been exploited, please contact secu...@kubernetes.io. Additional Details See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/142098 Acknowledgements This vulnerability was reported by the Kubernetes Third-Party Security Audit subproject, OSTIF, and Shielder. The issue was fixed and coordinated by: Yuanliang Zhang @zylxjtu Verónica López @Verolop Jeremy Rickard @jeremyrickard Nathan Herz @natherz97 Thank you, Nathan Herz on behalf of the Kubernetes Security Response Committee ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================