Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ebtablesd marked as malware #5656

Closed
canle1404 opened this issue Apr 2, 2024 · 2 comments
Closed

ebtablesd marked as malware #5656

canle1404 opened this issue Apr 2, 2024 · 2 comments

Comments

@canle1404
Copy link

Environmental Info:
RKE2 Version: v1.25.16+rke2r1

Node(s) CPU architecture, OS, and Version: Linux ***************-3ff50b01-r276g 5.4.0-1041-aws #43-Ubuntu SMP Fri Mar 19 22:06:16 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux

Cluster Configuration: 3 nodes

Describe the bug: We are using ORCA for scanning security and ORCA marked this file as malware /var/lib/rancher/rke2/agent/containerd/io.containerd.snapshotter.v1.overlayfs/snapshots/7/fs/usr/sbin/ebtablesd
VirusTotal scan result: https://www.virustotal.com/gui/file/c4af716f77714aa5dd16f570a76d4fc890cbcf17d1f7c7b1bed4aff2a67a127e

Steps To Reproduce:

  • Installed RKE2 cluster with Rancher
  • Get hash file: sha256sum /var/lib/rancher/rke2/agent/containerd/io.containerd.snapshotter.v1.overlayfs/snapshots/<snapshot ID>/fs/usr/sbin/ebtablesd
  • Copy the sha into https://www.virustotal.com/gui/home/search

Expected behavior:
image

Actual behavior:

image

Additional context / logs:

@canle1404
Copy link
Author

I think this issue will relate to k3s-io/k3s#9738

@brandond
Copy link
Member

brandond commented Apr 2, 2024

Yes, closing this as a duplicate of that issue.

@brandond brandond closed this as completed Apr 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants