PT-2025-18315 · Unknown+2 · Kubernetes+2
Published
2025-04-30
·
Updated
2025-05-07
·
CVE-2025-32777
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Volcano versions prior to 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2
Description
The issue is related to a privilege escalation that can cause denial of service of the scheduler. If an attacker compromises either the Elastic service or the extender plugin, the scheduler will become unavailable to other users and workloads in the cluster. The scheduler will either crash with an unrecoverable OOM panic or freeze while consuming excessive amounts of memory. This is possible because Volcano users may run their Elastic service and extender plugins in separate pods or nodes from the scheduler, and node isolation is a security boundary in the Kubernetes security model.
Recommendations
To resolve the issue, update to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, or 1.12.0-alpha.2.
As a temporary workaround, consider restricting access to the Elastic service and the extender plugin to minimize the risk of exploitation.
Restrict access to the pods or nodes where the Elastic service and extender plugins are deployed to prevent an attacker from crossing the security boundary.
Exploit
Fix
LPE
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elastic
Kubernetes
Volcano