Impact
A flaw in kronosnet’s cryptographic configuration management leaves raw encryption keys in memory after their containers are freed. The omission of proper zeroing or wiping allows a local attacker, who can employ memory disclosure techniques, to retrieve active encryption keys. Possession of these keys enables decryption of cluster network traffic and the injection of forged packets, potentially destabilizing high-availability environments and compromising the confidentiality of cluster communications.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 8, 9, and 10 as well as Red Hat OpenShift Container Platform 4 when using kronosnet version 1.34 or earlier.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw is limited to local attackers who can access process memory; it is not exploitable remotely. The vulnerability is not listed in CISA's KEV catalog. While the potential impact—decrypting cluster traffic and injecting malicious packets—could undermine system stability, the attacker’s local nature and the low exploitation probability recommend monitoring until an official patch is available.
OpenCVE Enrichment