VDB
Sign up
MEDIUM6.6

GHSA-jv3w-x3r3-g6rm

CNA Plugins Portmap nftables backend can intercept non-local traffic

Quick fix

GHSA-jv3w-x3r3-g6rm — github.com/containernetworking/plugins: upgrade to the fixed version with the command below.

go get github.com/containernetworking/plugins@v1.9.0

Details

### Background

The CNI `portmap` plugin allows containers to emulate opening a host port, forwarding that traffic to the container. For example, if a host has the IP 198.51.100.42, a container may request that all packets to `198.51.100.42:53` be forwarded to the container's network.

### Vulnerability

When the `portmap` plugin is configured with the `nftables` backend, it inadvertently forwards all traffic with the same destination port as the host port, **ignoring the destination IP**. This includes traffic not intended for the node itself, i.e. traffic to containers hosted on the node.

In the given example above, traffic destined to port 53 but for a _separate container_ would still be captured and forwarded, even though it was not destined for the host.

### Impact

Containers (i.e. kubernetes pods) that request HostPort forwarding can intercept all traffic destined for that port. This requires that the `portmap` plugin be explicitly configured to use the `nftables` backend. (The `iptables` backend is the default.)

### Patches This is fixed as of CNI plugins v1.9.0

### Workarounds Configure the `portmap` plugin to use the `iptables` backend. It does not have this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/containernetworking/plugins
Introduced in: 1.6.0Fixed in: 1.9.0
Fixgo get github.com/containernetworking/plugins@v1.9.0

References