PT-2025-17449 · Cilium · Cilium

Gandro

+1

·

Published

2025-04-21

·

Updated

2025-04-23

·

CVE-2025-32793

CVSS v3.1

4.0

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cilium versions 1.15.0 through 1.15.15 Cilium versions 1.16.0 through 1.16.8 Cilium versions 1.17.0 through 1.17.2
Description Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium.
Recommendations For versions 1.15.0 through 1.15.15, update to version 1.15.16 or later. For versions 1.16.0 through 1.16.8, update to version 1.16.9 or later. For versions 1.17.0 through 1.17.2, update to version 1.17.3 or later.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CILIUM-2025-32793
BIT-CILIUM-OPERATOR-2025-32793
BIT-HUBBLE-RELAY-2025-32793
CVE-2025-32793
GHSA-5VXX-C285-PCQ4
GO-2025-3635
OPENSUSE-SU-2025:15017-1

Affected Products

Cilium