oss-sec mailing list archives

cve request: docker swarm node Dos occurs when join a cluster failed using local CA certificate


From: Diogo Mónica <diogo.monica () docker com>
Date: Mon, 5 Sep 2016 16:26:02 -0700

From I can understand from this report, the author creates a swarm, messes
with the local certificate for a worker, and then tries to join the swarm.
The worker fails because the author messed with the local state.

This does not make the manager not available to the rest of the worker
nodes, and is essentially a self-DoS (I modified my local configuration in
such a way that docker doesn't run).

A simple rm -rf /var/lib/docker/swarm should clean all the state. Not CVE
worthy.

-- 
Diogo Mónica

Current thread: