CVE-2026-35172
distribution distribution, Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13 취약점
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.46% 백분위 37.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.07