# 7.16.2 triggering Google Cloud security alert

**URL:** <https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [December 21, 2021, 10:41pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618 "2021-12-21T22:41:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![gehgerds](https://avatars.discourse-cdn.com/v4/letter/g/22d042/32.png) [@gehgerds](https://discuss.elastic.co/u/gehgerds)\
**Post date:** [December 21, 2021, 10:41pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/1 "2021-12-21T22:41:20Z")

</div>

After bumping the docker image version to elasticsearch:7.16.2 in GKE, whenever I start elasticsearch pod, it immediately triggers a security alert **Added Library Loaded**

> Added\_Library\_Fullpath: /tmp/twIW2T (deleted)  
> description: A library that was not part of the original container image was loaded. If an added library is loaded, this is a possible sign that an attacker has control of the workload and they are executing arbitrary code.  
> Process\_Binary\_Fullpath: /usr/share/elasticsearch/jdk/bin/java

This issue doesn't occur with 7.14.0 image version. Which I'm upgrading from.

---

<div class="post-metadata">

**Author:** ![gehgerds](https://avatars.discourse-cdn.com/v4/letter/g/22d042/32.png) [@gehgerds](https://discuss.elastic.co/u/gehgerds)\
**Post date:** [December 22, 2021, 5:13pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/2 "2021-12-22T17:13:18Z")

</div>

I'm also seeing the following stack traces at the container startup. But not sure if it's related to the above added library.

```auto
{"type": "server", "timestamp": "2021-12-22T17:08:21,937Z", "level": "ERROR", "component": "o.e.i.g.DatabaseNodeService", "cluster.name": "es-cluster", "node.name": "es-cluster-data-2", "message": "failed to download database [GeoLite2-Country.mmdb]",
"stacktrace": ["org.elasticsearch.cluster.block.ClusterBlockException: blocked by: [SERVICE_UNAVAILABLE/1/state not recovered / initialized];",
...
{"type": "server", "timestamp": "2021-12-22T17:08:21,939Z", "level": "ERROR", "component": "o.e.i.g.DatabaseNodeService", "cluster.name": "es-cluster", "node.name": "es-cluster-data-2", "message": "failed to download database [GeoLite2-City.mmdb]",
"stacktrace": ["org.elasticsearch.cluster.block.ClusterBlockException: blocked by: [SERVICE_UNAVAILABLE/1/state not recovered / initialized];",
...
{"type": "server", "timestamp": "2021-12-22T17:08:21,936Z", "level": "ERROR", "component": "o.e.i.g.DatabaseNodeService", "cluster.name": "es-cluster", "node.name": "es-cluster-data-2", "message": "failed to download database [GeoLite2-ASN.mmdb]",
"stacktrace": ["org.elasticsearch.cluster.block.ClusterBlockException: blocked by: [SERVICE_UNAVAILABLE/1/state not recovered / initialized];",
...

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 22, 2021, 8:01pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/3 "2021-12-22T20:01:11Z")

</div>

Yup it is probably related to that.

Perhaps read this..

> **[GeoIP processor | Elasticsearch Guide \[7.16\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/geoip-processor.html)**

Elasticsearch downloads the latest GeoIP databases.

You can set this.. but you should understand the impact

`ingest.geoip.downloader.enabled : false`

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 23, 2021, 9:32am UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/4 "2021-12-23T09:32:52Z")

</div>

> [@stephenb](#):
>
> Yup it is probably related to that.

I would not expect downloading a GeoIP database to trigger this message, although I don't have any great alternative ideas either.

As a rule it's best not to investigate potential security issues in a public thread. Please follow the instructions on [this page](https://www.elastic.co/community/security) instead.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 23, 2021, 3:08pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/5 "2021-12-23T15:08:41Z")

</div>

I am not as familiar with this exact error but I have worked with other containerization technology example Pivotal Cloud Foundry that would raise to his type of error because the expectation / policy is that container image is immutable and thus any changes / updates to the container would violate the security policy.

It may be something else instead.

@DavidTurner is correct please follow up using the procedure on the page he provided.

---

<div class="post-metadata">

**Author:** ![henrist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/henrist/32/99488_2.png) [@henrist](https://discuss.elastic.co/u/henrist)\
**Post date:** [December 23, 2021, 3:52pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/6 "2021-12-23T15:52:15Z")

</div>

This is caused by the updated version of JNA and libffi.

Here's the code that writes that tmp file and memory maps it with executable flag: [jna/tramp.c at 5.10.0 · java-native-access/jna · GitHub](https://github.com/java-native-access/jna/blob/5.10.0/native/libffi/src/tramp.c#L255-L277)

This happens when a method is registered via JNA during call to [ffi\_closure\_alloc](https://github.com/java-native-access/jna/blob/5.10.0/native/dispatch.c#L3493).

(This is what is written there: [jna/unix64.S at 5.10.0 · java-native-access/jna · GitHub](https://github.com/java-native-access/jna/blob/5.10.0/native/libffi/src/x86/unix64.S#L519-L530))

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 23, 2021, 4:52pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/7 "2021-12-23T16:52:37Z")

</div>

> [@stephenb](#):
>
> any changes / updates to the container would violate the security policy.

The fact that a library was created and dynamically loaded isn't surprising, Elasticsearch has used JNA for many years which does this (perhaps not always, but it's always been a possibility). What's surprising is the filename: JNA's filenames typically contain the string `jna` and I thought libffi would [include the string `ffi` too](https://github.com/java-native-access/jna/blob/5.10.0/native/libffi/src/closures.c#L594), but @henrist is right that it doesn't always.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 23, 2021, 11:16pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/8 "2021-12-23T23:16:53Z")

</div>

Today I Learned.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 20, 2022, 11:17pm UTC](https://discuss.elastic.co/t/7-16-2-triggering-google-cloud-security-alert/292618/9 "2022-01-20T23:17:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
