Database/Control plane, storage & DevOps
MinIO (S3 Select): A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process is
Impact
A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process is OOM-killed. One tenant issuing a single query takes down the shared object store for every job on the cluster.
Who can reach it
Any authenticated tenant that can issue S3 Select queries against the endpoint.
What to do
Upgrade to the release in GHSA-h749-fxx7-pwpg and restart the nodes. If S3 Select is not used by your workloads, deny SelectObjectContent in the bucket policy. Set a memory cgroup limit on the MinIO service so an allocation blowup restarts one node instead of destabilising the host.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.