Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-26031

Apache Hadoop YARN: container-executor loads libraries from a relative path, allowing root escalation

Technology

Apache Hadoop

CVSS Score

7.5 / 10.0

Affected Versions

3.3.1 to 3.3.4

Upstream Fix

3.3.5

Published

November 16, 2023

OSSeva Coverage

Fixed upstream

Description

YARN-10495 changed the library path of the setuid-root container-executor binary to include ../lib/native/, so a local user can place a malicious libcrypto library where it will be loaded and run as root. If the cluster runs remote users' jobs on the host rather than in containers, remote users may gain root. The fix reverts the change. A container-executor without the suid bit, which does not support YARN Secure Containers, is not exploitable.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 3.3.1 to 3.3.4, you need this patch. Book a discovery call to get covered.