PT-2025-4775 · Cilium+1 · Cilium+1

Kokelley-Cisco

·

Published

2024-11-29

·

Updated

2025-09-03

·

CVE-2025-23028

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cilium versions 1.14.0 through 1.14.7 Cilium versions 1.15.0 through 1.15.11 Cilium versions 1.16.0 through 1.16.4
Description A denial of service vulnerability affects Cilium, a networking, observability, and security solution with an eBPF-based dataplane. In a Kubernetes cluster where Cilium is configured to proxy DNS traffic, an attacker can crash Cilium agents by sending a crafted DNS response to workloads from outside the cluster. For traffic that is allowed but without using DNS-based policy, the dataplane will continue to pass traffic as configured at the time of the DoS. For workloads that have DNS-based policy configured, existing connections may continue to operate, and new connections made without relying on DNS resolution may continue to be established, but new connections which rely on DNS resolution may be disrupted. Any configuration changes that affect the impacted agent may not be applied until the agent is able to restart.
Recommendations For Cilium versions 1.14.0 through 1.14.7, update to version 1.14.18. For Cilium versions 1.15.0 through 1.15.11, update to version 1.15.12. For Cilium versions 1.16.0 through 1.16.4, update to version 1.16.5. As a temporary workaround, consider restricting access to the DNS proxy until a patch is available. Avoid using the DNS-based policy for new connections until the issue is resolved.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-06214
BIT-CILIUM-2025-23028
BIT-CILIUM-OPERATOR-2025-23028
BIT-HUBBLE-RELAY-2025-23028
CVE-2025-23028
GHSA-9M5P-C77C-F9J7
GO-2025-3415
OPENSUSE-SU-2025:14710-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Affected Products

Cilium
Suse