PT-2025-18315 · Unknown+2 · Kubernetes+2

Published

2025-04-30

·

Updated

2025-05-07

·

CVE-2025-32777

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Volcano versions prior to 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2
Description The issue is related to a privilege escalation that can cause denial of service of the scheduler. If an attacker compromises either the Elastic service or the extender plugin, the scheduler will become unavailable to other users and workloads in the cluster. The scheduler will either crash with an unrecoverable OOM panic or freeze while consuming excessive amounts of memory. This is possible because Volcano users may run their Elastic service and extender plugins in separate pods or nodes from the scheduler, and node isolation is a security boundary in the Kubernetes security model.
Recommendations To resolve the issue, update to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, or 1.12.0-alpha.2. As a temporary workaround, consider restricting access to the Elastic service and the extender plugin to minimize the risk of exploitation. Restrict access to the pods or nodes where the Elastic service and extender plugins are deployed to prevent an attacker from crossing the security boundary.

Exploit

Fix

LPE

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32777
GHSA-HG79-FW4P-25P8
GO-2025-3656
OPENSUSE-SU-2025:15059-1

Affected Products

Elastic
Kubernetes
Volcano