v1.10.13-lts.1

This is the first fixed release by KLTS for v1.10.13.

Patches

  • CVE-2019-11245

    Containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node.

  • CVE-2019-1002101

    This vulnerability may allow an attacker to modify or monitor any file in the directory with the same name in the symbolic link header during the unpacking process of the kubectl cp command, thereby causing damage.

  • CVE-2019-11246

    This vulnerability may allow an attacker to use the kubectl cp command to write malicious files in the container tar package to any path on the host using Path Traversal. This process is limited only by the system permissions of the local user.

  • CVE-2019-11248

    The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port.

  • CVE-2019-11249

    This vulnerability may allow an attacker to use the kubectl cp command to write malicious files in the container tar package to any path on the host using Path Traversal. This process is limited only by the system permissions of the local user.

  • CVE-2019-11251

    This vulnerability may allow an attacker to use the kubectl cp command to write malicious files in the container tar package to any path on the host using Path Traversal. This process is limited only by the system permissions of the local user.

  • CVE-2020-8552

    This vulnerability may make the API Server vulnerable to a DoS (Denial of Service) attack caused by successful API requests.

  • CVE-2021-3121

    A program with this vulnerability may crash because of processing some messages that contain malicious Protobuf. If the version of Gogo Protobuf you are using is too low, this vulnerability may exist.

  • nokmem

    The node has sufficient disks, but it keeps reporting that the disk is insufficient to create a Pod.


Last modified April 15, 2026 : Update v1.10.13-lts.1.md (11d889e0)