Description
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
Problem types
Product status
Any version before 0.15.2
v4.17.39-2 (rpm) before *
v4.18.25-3 (rpm) before *
v4.20.3-3 (rpm) before *
sha256:525c4d55fde92557bd0c3123961cb32eee28edca3aaa884e224d5efa4f3c4f83 (rpm) before *
sha256:e043fdf674a120f56d62a0c6ff2b91bc8c61875d5ce371abc3540714928e0528 (rpm) before *
sha256:822fc16687164f666df5e498030bec3d3ab1e07d0a0576cc133a468e4ea01cf2 (rpm) before *
sha256:46013beb1d8f782e92088ad4ea2d10155c67edb8d613966a5c069340bcac5ddd (rpm) before *
sha256:f9a38a9960a716f58f5ba7b07df9c6d2fa4527d5fffe0eba5dc190b4762019d1 (rpm) before *
sha256:a1bcab43a493a6452acb4bc80f69da3f226fa70e676e8a66e97e92fb50b5fada (rpm) before *
sha256:ba619fd1055ec06103c2e32806b2c8b3fd13e8a1388f90c70aec862c5d153c8f (rpm) before *
sha256:4d872d919c09d08132e0e056a60ad1e4c457fc600cd0521b0160d7f5106f4ea3 (rpm) before *
sha256:c46f71fd1c155408171643cf823e5af50f425eef10d883819156d044f8158361 (rpm) before *
sha256:107beee845fb13ddcb1c327a2a5fe705cc2f599c775786f937e17c0720977777 (rpm) before *
sha256:dd99548b21e36ba637fbf8e44f6062d2fec98abd536dba16e10475648664984e (rpm) before *
sha256:4364624686c53f5996960296f8ce496ee819d500eab396f35f7bf417dfdf08b9 (rpm) before *
sha256:0488dca3cb2db097732fe153483af7c4b2acdb7b0bc241f30e78cdb0474d11bb (rpm) before *
sha256:b996388849ae27f7721c24987d19e8f0b561ba3c0d03496c89fe1d987a64fe7e (rpm) before *
sha256:c5e7e0f82b73bcdfc594b25ecb2273819fd28dfbbecb4045f997da3d18a398dd (rpm) before *
sha256:7ccd6c3cf13980e73689da2a969cb29c1875e3bd4a76999a76f588f9f0cde8dd (rpm) before *
sha256:295cce4181249098c7903b70ef34afe257731e062c9cb944845663929ca8075c (rpm) before *
sha256:17ff83445d5f6c2296f1b5c5061734a7866c84f6951e140f194bb5a1b2c981a2 (rpm) before *
sha256:dd99548b21e36ba637fbf8e44f6062d2fec98abd536dba16e10475648664984e (rpm) before *
sha256:4364624686c53f5996960296f8ce496ee819d500eab396f35f7bf417dfdf08b9 (rpm) before *
sha256:0488dca3cb2db097732fe153483af7c4b2acdb7b0bc241f30e78cdb0474d11bb (rpm) before *
sha256:82750019c353c3185dc35fb68a675c9d758a3022144855ac09bad49fa4ac3daa (rpm) before *
sha256:c5e7e0f82b73bcdfc594b25ecb2273819fd28dfbbecb4045f997da3d18a398dd (rpm) before *
sha256:7ccd6c3cf13980e73689da2a969cb29c1875e3bd4a76999a76f588f9f0cde8dd (rpm) before *
sha256:295cce4181249098c7903b70ef34afe257731e062c9cb944845663929ca8075c (rpm) before *
sha256:17ff83445d5f6c2296f1b5c5061734a7866c84f6951e140f194bb5a1b2c981a2 (rpm) before *
sha256:e69f76da9ffe324bd5b82eaf453bf36198dfc593e2646a81efc157b386e92734 (rpm) before *
sha256:b080a37e6dbb9dea9bba1fc1c19865988021db3c90b439882b551c996083a54b (rpm) before *
sha256:b2f35172ddbdd878d0c84dbfc623efd2cb32b9d86bbbdcc5bb1386ddba184796 (rpm) before *
sha256:c0aafa96779a5a2c4d8d01c1e3d27f3d2dc51829c780cea401b7729788898765 (rpm) before *
sha256:448f802fa1a8d8d762ce1c1a20844bad5bdec44adc9fcf65f6fc426f2f48ec43 (rpm) before *
sha256:56a7d375e7bca09b0d7f12c312414bd04c6a60b59119e9787cf55a9dc5f82626 (rpm) before *
sha256:1d1deb4104d8aeec314f451c168913fd389ac2d8b1380a68e8722c860ea4cb16 (rpm) before *
sha256:191621a5e2afecd2c48008e3922403d0dee3651085e68e404e23b87db54e6903 (rpm) before *
sha256:4f7a00583f8fe10b6fb076c75123c3fa49d9cfa0c89081d3bb39ed347f4c0993 (rpm) before *
sha256:e268332aeeeebd1d10688d513fa422c1ddf6d2e448f558ddae25ac719dc4f608 (rpm) before *
sha256:3d3c96fd84e118f8236161bf16f22e2456a84fb38b0cd80406e97ada5149d30f (rpm) before *
sha256:869e84f8f70932a52daa3e2ab00edf51d307c5e765e96f4f60959f9f048299ff (rpm) before *
sha256:3a315a6e64edc354b066358fb29a64e9c7661d1ee9e634c084cb972d87329dc9 (rpm) before *
sha256:5ad05f728a9409bccca7af882d0bb7161a2269d8336ad3e63c3236c9023e017a (rpm) before *
sha256:e9a01f91576307ab1e618ce7e4db1c116b2eb9701c5f5a48b0ad671fa57dc18d (rpm) before *
sha256:f2b3e838d78b6bd89e5c9f401326d08696fb29b862fa99b701a3b0aa8b705fe4 (rpm) before *
sha256:dc57216ee72653b47f144eaec5673ace76df32a1178f98edf999578b3a467971 (rpm) before *
sha256:e81a79083584a213a6f23ac6596b4249a2ec4c93982fe71e5a5919b71b7f3962 (rpm) before *
sha256:06d861b23cf7f8622e14d577d87ab1da07b1ebe7caaa51f4ebb7216f9435ada4 (rpm) before *
sha256:a01b582bf6eb19385e30a2c74957b111f71242059500c3c568c8e0dd1d6683a9 (rpm) before *
sha256:37c6415ccd9a7a41d99d67ebe5ffd33c54d723c23e9cb744ea0626a9ab5b7854 (rpm) before *
sha256:dbb96a4e7584a48e7a61a00485ccbcb23919dcbdd47af01cec452bd4f0fd0bdc (rpm) before *
sha256:7e2deb1a27aa0b83ae76b48abf19d386600275812f4fa7edd1ff38c1989e02dc (rpm) before *
sha256:5018f06c42442fa004f7d726669f500ac171193008959415bb1f101b94106dc9 (rpm) before *
sha256:38019d9ba07f59515345dddcd1800da3408be06b3620f4b1c1dd2034e939d26b (rpm) before *
sha256:0fa09c7b7e469826f9788e24cffedea3a90a456af78d4a3237fecb99a3ad52a1 (rpm) before *
sha256:dbb96a4e7584a48e7a61a00485ccbcb23919dcbdd47af01cec452bd4f0fd0bdc (rpm) before *
sha256:e1560f85d5351cdf0f0fb90e7d13506a7bb5a0da0a0f414db7b82ca87192912b (rpm) before *
sha256:54b289b9be542339fe66563414c41797b47be201e87ada73b690d566513d7459 (rpm) before *
sha256:e1560f85d5351cdf0f0fb90e7d13506a7bb5a0da0a0f414db7b82ca87192912b (rpm) before *
sha256:4e61bb2cc124f37ec9c009e9ee92bfa638ff608f2b28962abbe1ff5614b99155 (rpm) before *
sha256:54b289b9be542339fe66563414c41797b47be201e87ada73b690d566513d7459 (rpm) before *
sha256:844cb73f99650653f57b64fa478ae4d0b207cd60040cdbd743bca7fd76af30ea (rpm) before *
sha256:c13595e478ea28b6ba8d146d5a93c6f271babf253653d914139000e5af34d022 (rpm) before *
sha256:d8f0bb2246c301858cad1107e166466bd3df41817e245d9955ca2a441866bd23 (rpm) before *
sha256:e11fa23f27e11118273b98b57137f42dbbea9b18df0a55e674662cb12522bae5 (rpm) before *
sha256:7e394d47079a8bbe2a4a1f158725ddb6b6c7c184c48ee22dd8873b1b8e4e642f (rpm) before *
sha256:e5e7d3e715c21d58322704974d82acd21bf33b87ad4218d32a7c478e1efc8bf8 (rpm) before *
sha256:46b615cf682815259b0c4b9e785d2f0b429726f75920f7ce9c31625ac86118b2 (rpm) before *
sha256:e3b54d5763bdae0de90ea53588d4fa8bf5476ba75c0423d40b334286017c7655 (rpm) before *
sha256:c3e482ed74cff4b39cdb5450fe3387c15c998849b6c6b83bf794b7b241f1c78b (rpm) before *
sha256:b8d389436f0ac6d75dfcd0b203f2f5b0e1b0e2e24285b9a5bedf9f74f1a14028 (rpm) before *
sha256:931fcca9e7cb6f6c7454a72b533cbe4d767438e374848b846f079a3c2d323901 (rpm) before *
sha256:0a88403bb113a735853cc289bad5c2b5e650e5f9d28e28cf635c2fef808025b1 (rpm) before *
sha256:152c336c76cc69fc11cd6d3957c781c8d1c733a3cbead2448efd202b35d034e2 (rpm) before *
sha256:f6bb9ef4fdc334383afeb77f5db81543ed3657186402912c374cefdf4e90588e (rpm) before *
sha256:0a0e70953d2217d929b55a7a7a4c1e49c7e5f6b196b693312c252bfec2dc3843 (rpm) before *
sha256:645d5fca647a051a1a23a25f577aa4a7d6520611c97c5232868a49e41156af9e (rpm) before *
sha256:d3850e64b6707d4fa8c87efd652e4b06ee122c58fe43040b371295626f7d3784 (rpm) before *
sha256:ab7a97cfde454612e61f37486bdddca9e9c449c6ea75da71f2399d35de63ae3a (rpm) before *
sha256:0d8ff43ca27a8ca5017fc136f9708c743043b72479bced7ce7a91c1057d92339 (rpm) before *
sha256:8d131c609dea271df0cf754e7d28cdb79ad45012c5359f61b13713f9467c8e32 (rpm) before *
sha256:f011d15924cc17887a92b01285d253add0b738c1551ee6c9efef88e123e607ef (rpm) before *
sha256:07fade8638107be11d2eb1fe76cd0e051627d85a28aa00e677e82764d94b9bee (rpm) before *
sha256:d10840f73008b75bd8550baa67ce453e27ae44bfdb4515fe53752078d460edfb (rpm) before *
sha256:823fc904b55808456d855bd842a77db55a66ef0f56c8fdc00cd7812c0c865fcc (rpm) before *
sha256:babfb7fa894d83f591bd3bb17621a440bd9e6e001e4530a01de65bb36fc025b5 (rpm) before *
sha256:9592e63b97947aa2f4a695c7c727bef327595d84350640a3dac51de86ef08e07 (rpm) before *
sha256:9cd712406fc8f8b479695d4857ae1f242e32ac9d54bc6b692cb3755837b1a92b (rpm) before *
sha256:70eeb29f70f8d78e702fad26d13875cd36bfcf6aea7d2b9415dded2b526a73ef (rpm) before *
sha256:78175febe7b181ade5054857d20b097797663c72cb17cbae4203958e8a351329 (rpm) before *
sha256:c9cfe4871323f9cf38c238bca0550c26f7b4e788a0a7b8d052d8f1fe549c6a3b (rpm) before *
sha256:342ec40b4be75a43a6dc9bd86bdd684ffad05c04e177a173273f1d892e2501dd (rpm) before *
sha256:d53c5343851957d291397d11fb14f4b52a1b0e5dbd9a305a3eaf66c45e9b6228 (rpm) before *
sha256:e9fa24dc675a9061b4fd8b8bcc16e0e87f1beb89df2ad770f7b19fb935052cd4 (rpm) before *
sha256:65faa431e4154804f3b3330e37bf97ebfc4a5fbe2ece950e54a50827dd1848e7 (rpm) before *
sha256:2afaf7feceda2596f257888a5cc5dd19293252da973d4988e00a21c50aa601c4 (rpm) before *
sha256:cfcebf800eef83a2682f1ece6c77c4328e58bffac7a660816e52f4f8784ee579 (rpm) before *
sha256:78215ea775ed2c537d7a22f9c5107e0e07089c85f19ba9c3cc7ba40af3efc9bc (rpm) before *
sha256:823e0e164ee8b775d43da7e14858ab3af2d4a02d1ab61b8e9059374db8aed53e (rpm) before *
sha256:eb634b55b2a817539013d61747dd359e5d9cb66a636d7308d6e91090203bea3e (rpm) before *
sha256:0c5becf0a62d24cb986b0338432e30fa1952487392d3712d190c85f35300cd97 (rpm) before *
sha256:896c0fef09071c686fdebff7afe1133e06fca18271525367df08491fb49c5490 (rpm) before *
sha256:4f2e39222f959dccc6938430518c38f154f3c43d5975549be11c703067d4c074 (rpm) before *
sha256:12451b0a143da79ef8012629abdf852c94a2388e0fc35cf0d550493a430b5d67 (rpm) before *
sha256:55604e05935f27a493571fde6dc84efe20f1480b00bf2918389d0c3df8dbea9c (rpm) before *
sha256:61acc4a0fae3f3a706ef70a08f7bf10b2773299c0fdd546705028483a02cd241 (rpm) before *
sha256:fa357f2d2f856c7e3cf444b6fe0959bf7663a12dab6fb0965e5f110db479697d (rpm) before *
sha256:88ee659ec3dee8762aef89123cab66c71e58cf473af2b1f3c9abfff65d645c50 (rpm) before *
sha256:f1c8c40ee99ee53c66bba5a4d81c87f1396097316f31dec48a1646701f41f232 (rpm) before *
sha256:8c9693993390434902aef2af7beb58823b8646dad7f3ac317ec7e7faafde9767 (rpm) before *
sha256:2157276d6715734095eccf19ee2a3b8ee2610831e6db28db4d1549a45ef1226f (rpm) before *
sha256:c2f92235f218700f0d19cda4ae7e2d58689f82f4d31e1e97aa446ae6658a7c64 (rpm) before *
sha256:be114324106bac45e644e8a4c13dad7699e8808fcaf7da535fe9e7cdc06f1796 (rpm) before *
sha256:28fecbad41a6b90ed64ff1ed6d36acf4cf88a8f86131556d6d8ba35766c9a70e (rpm) before *
sha256:69ae289c4b1a9a51a25813d996d7f14794bcddc39df0512cc6e8effc6e32ad16 (rpm) before *
sha256:51e41acedaa776080b4f8a297d13d4f609839b834d929f4312a2c70afdb68329 (rpm) before *
sha256:0569ea1b4783e21b056242d9f2a40a548ff560a5ab957245444cc3770ed664db (rpm) before *
sha256:924467600e2487103c8a1d4cd83df9afd3ae4ac8c0bb5442fe85f22b96c77d1a (rpm) before *
sha256:f1461bb91214c8fce0a143e00353c7e61abd374e31476dc71beaa6d75a2d0847 (rpm) before *
sha256:cd9a58d3ac10d7ac072ad056ff897565308e798cd0bb8ce50248924fa6f904c5 (rpm) before *
sha256:4af5cbf6944b170e3578f0e904a57acbdef4ce27b7dbd9629b2a4d7c0231330d (rpm) before *
sha256:1985673ff4c5b1df5b030031b2537af107134ecbe51087474f0b8ae7c3aa3c90 (rpm) before *
sha256:b0b7b38bcb61288eaf3a7f7339ed0b2f4dbbf463f71ee6f64400dbecbf995d31 (rpm) before *
sha256:04037c00520f7f909565b6461455f0878a54d9f879b328708872c7f03bd24175 (rpm) before *
sha256:875e86d19b02583156eb12fc726b5089a377403088389997383c0c986e3b2fc1 (rpm) before *
sha256:b85b442e7736f1513f25a7278881b5adcfc04fdf0e55546358824459efdbd820 (rpm) before *
sha256:12bd5b3aec0dbd7bd29e10956eae9986ab95591918e4331ef495ba9480e13338 (rpm) before *
sha256:2a9ecf79a8209fb80fc189c2a05b68ebb3874dd2e1c404361f3b26533188e6a1 (rpm) before *
sha256:c0a8b08176be1737fb15f9e68444b7fe56678071518253ed3ad82c9f9c0bb8d5 (rpm) before *
sha256:52b41ec0e8f6f6e5f39aa2f1c173eef364fcae6e78a8c6091f0c6b3583221034 (rpm) before *
sha256:4b3115829f2443bc90d15421da6e0679d7f9364639a46bd43aa858ec5e2109f7 (rpm) before *
sha256:e661ba3760dbd154ca7fcac8ceb39a50403664e712f43a93c4732b7e078de7aa (rpm) before *
sha256:fe9ac9f019ce9b181a62d0e5ec9057e841bd3f5f696eefbb44fe48f50308d740 (rpm) before *
sha256:1fba962b878b4ea0e7aa9f124e2a1f6e995ef43f3eb6eb970d18e70b813711c5 (rpm) before *
sha256:e31f40647bbc4b33f18a76bf4e91003db8310eedcb5552e27b4e0189612ddfb9 (rpm) before *
sha256:1feecf8d8b8d2cbc52990a41805d80b8681763b1e3f8302b2d1e210582b8f6cf (rpm) before *
sha256:f1ffce4025a69919c719a68acc3947920a232dcfa1d7b5987aadcaf3f88e0481 (rpm) before *
sha256:05662182c4c1d373d36066294c7f927d63ef85c6f0922ced8612a2eb8bd7d925 (rpm) before *
sha256:ce4d79d310a644286872f9026bab2fe0725b4fc9baf230b407bc5eb5326c8136 (rpm) before *
sha256:6336c817d1bcbce9677ca5d525ceedd28789cbde1384cf7a606608168f4e0f10 (rpm) before *
sha256:06cffda6829fdcc6ecb2b2da7dfa2bf090f0755867e2569f7ce14d1d57f6080a (rpm) before *
sha256:e35ebfe16a9f5696dad58a2c1dc0d081125cf822a293c6bfdbebe4423e79438f (rpm) before *
sha256:fe2f268a94607d73be5e1f1a9d575cdf5e4805dc1049bd0d0e09e52303920c4b (rpm) before *
sha256:8689f95dfb32aafea228ef08e290949cc3c31e6a2acbb0f66da02ef0cf84089c (rpm) before *
sha256:b251e7b26d4a6f3443d6d795a4d92992b5f79d56e5561477648eabae286d7641 (rpm) before *
sha256:7c02ce667bc7b6693596ba249e34d7233a95fdb1966ce317927b2363518a564f (rpm) before *
sha256:e0d3839cbb1734c0e224e0c076c7c8b4d0e0888e31989b8a6a611418ea2c72bc (rpm) before *
sha256:00bdcca61bc8765fbbc838deeb86392ce25c72f0170241c270484ec9b77bd263 (rpm) before *
sha256:49f1e7092bdd19f318580b3d4dfc37dbec8435f814b7d1b863ed34a6ba6157ee (rpm) before *
sha256:a492d94ceced107b6b8dc7339cca181875d2245c5f8ac9ecc51979160a341d76 (rpm) before *
sha256:5aad1d226292a42c700e97575eec56040108869acdcb720a9c5b32d02a0035b3 (rpm) before *
sha256:4d0f4fe708b4aea53b1bbf71fb10a41fd50313d62fb380b7cafd6abb130b5024 (rpm) before *
sha256:c786effa06598ecb80690644d1c9075588e123ad200db05686568a80a1feeb56 (rpm) before *
sha256:b14c3a7c4cc6531ed0d9701fe1b07ddc8c85e702ef8b058f0eaaadb1e8852a04 (rpm) before *
sha256:173a4998c70c4c8ff9d0d4f90fb48e8e3d3f8fbc4deeb4f742cbaa38dda61215 (rpm) before *
sha256:d56cef998bb118950349234aacabc55dd066bb065b3502206505b1f7b01534c4 (rpm) before *
sha256:40f8584e7ed0be1742fc3d40ee639dfd5323e38c55c7fcae4146d4246abf6cf0 (rpm) before *
sha256:7c5b233911109f0a218b634d8d317229a3949b2ea5936b7ec91ebfcdd6f15060 (rpm) before *
sha256:053ad72159390ad37825015b051252dc162f46ebeeab4866e1568af1f0084cab (rpm) before *
sha256:ca0284c10827905e1576ea0a01bb09425acbf96d30b2e556b34e22e2d0115196 (rpm) before *
sha256:c988f8015f90581e97bb97210853d417b7f090e62d39a0469865e1628a9dbbd3 (rpm) before *
sha256:83746838d5b190c09d22dd1cc34c7d4822022534c624be10854bd9b660713932 (rpm) before *
sha256:f0fc8196ffce6f355f06c0157a38e36109eaa9be1f3e91ad71fdd72bc33ee509 (rpm) before *
Timeline
| 2025-07-04: | Reported to Red Hat. |
| 2025-08-07: | Made public. |
Credits
Red Hat would like to thank Antony Di Scala, James Force, and Michael Whale for reporting this issue.
References
access.redhat.com/errata/RHEA-2025:23406 (RHEA-2025:23406)
access.redhat.com/errata/RHEA-2025:23478 (RHEA-2025:23478)
access.redhat.com/errata/RHEA-2026:0129 (RHEA-2026:0129)
access.redhat.com/errata/RHSA-2025:19332 (RHSA-2025:19332)
access.redhat.com/errata/RHSA-2025:19335 (RHSA-2025:19335)
access.redhat.com/errata/RHSA-2025:19958 (RHSA-2025:19958)
access.redhat.com/errata/RHSA-2025:19961 (RHSA-2025:19961)
access.redhat.com/errata/RHSA-2025:21368 (RHSA-2025:21368)
access.redhat.com/errata/RHSA-2025:21885 (RHSA-2025:21885)
access.redhat.com/errata/RHSA-2025:22415 (RHSA-2025:22415)
access.redhat.com/errata/RHSA-2025:22416 (RHSA-2025:22416)
access.redhat.com/errata/RHSA-2025:22418 (RHSA-2025:22418)
access.redhat.com/errata/RHSA-2025:22420 (RHSA-2025:22420)
access.redhat.com/errata/RHSA-2025:22683 (RHSA-2025:22683)
access.redhat.com/errata/RHSA-2025:22684 (RHSA-2025:22684)
access.redhat.com/errata/RHSA-2025:23528 (RHSA-2025:23528)
access.redhat.com/errata/RHSA-2025:23529 (RHSA-2025:23529)
access.redhat.com/errata/RHSA-2025:23542 (RHSA-2025:23542)
access.redhat.com/errata/RHSA-2026:0627 (RHSA-2026:0627)
access.redhat.com/errata/RHSA-2026:0718 (RHSA-2026:0718)
access.redhat.com/errata/RHSA-2026:0722 (RHSA-2026:0722)
access.redhat.com/errata/RHSA-2026:0737 (RHSA-2026:0737)
access.redhat.com/errata/RHSA-2026:2572 (RHSA-2026:2572)
access.redhat.com/security/cve/CVE-2025-7195
bugzilla.redhat.com/show_bug.cgi?id=2376300 (RHBZ#2376300)