CVE-2026-101295 oc-mirror 目录遍历任意文件写入漏洞
影响攻击者可写入任意路径文件,可能导致代码执行或系统被入侵
oc-mirror 是 OpenShift 用于镜像 operator catalog 等内容的命令行工具。该漏洞存在于其解压 catalog 镜像层 tar 条目的过程中,未校验文件路径是否位于目标目录内。使用 --v1 或 --use-oci-feature 路径镜像 operator catalog 时均可触发。
影响范围
受影响版本范围暂无公开信息,涉及使用 --v1 或 --use-oci-feature 选项处理 operator catalog 镜像的 oc-mirror 版本。
漏洞详情
漏洞类型为路径遍历(CWE-22)导致的任意文件写入。成因是 oc-mirror 在解压 catalog 镜像层中的 tar 条目时,未验证条目路径是否解析到预期目标目录内,从而允许 ../ 等相对路径逃逸。攻击者可通过构造恶意 catalog 镜像,使解压过程将文件写入目标目录之外的任意位置。
利用条件与风险
利用前提是受害者使用 oc-mirror 镜像攻击者可控的恶意 operator catalog 镜像。实战中可覆盖配置文件或写入可执行文件,造成权限提升或代码执行,风险较高。
修复建议
官方修复方案暂无公开信息,建议关注 oc-mirror 项目及 OpenShift 官方安全公告并及时升级。临时缓解措施包括仅镜像可信来源的 catalog 镜像,并避免在特权环境中处理不可信镜像。
Path traversal / arbitrary file write in oc-mirror’s operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (–v1) or the OCI feature path (–use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.