CVE-2023-26031
Apache Hadoop YARN: container-executor loads libraries from a relative path, allowing root escalation
Technology
Apache Hadoop
CVSS Score
7.5 / 10.0
Affected Versions
3.3.1 to 3.3.4
Upstream Fix
3.3.5
Published
November 16, 2023
OSSeva Coverage
Fixed upstream
Description
YARN-10495 changed the library path of the setuid-root container-executor binary to include ../lib/native/, so a local user can place a malicious libcrypto library where it will be loaded and run as root. If the cluster runs remote users' jobs on the host rather than in containers, remote users may gain root. The fix reverts the change. A container-executor without the suid bit, which does not support YARN Secure Containers, is not exploitable.
Is your Apache Hadoop deployment affected?
If you're running 3.3.1 to 3.3.4, you need this patch. Book a discovery call to get covered.