PT-2025-4775 · Cilium+1 · Cilium+1
Kokelley-Cisco
·
Published
2024-11-29
·
Updated
2025-09-03
·
CVE-2025-23028
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cilium versions 1.14.0 through 1.14.7
Cilium versions 1.15.0 through 1.15.11
Cilium versions 1.16.0 through 1.16.4
Description
A denial of service vulnerability affects Cilium, a networking, observability, and security solution with an eBPF-based dataplane. In a Kubernetes cluster where Cilium is configured to proxy DNS traffic, an attacker can crash Cilium agents by sending a crafted DNS response to workloads from outside the cluster. For traffic that is allowed but without using DNS-based policy, the dataplane will continue to pass traffic as configured at the time of the DoS. For workloads that have DNS-based policy configured, existing connections may continue to operate, and new connections made without relying on DNS resolution may continue to be established, but new connections which rely on DNS resolution may be disrupted. Any configuration changes that affect the impacted agent may not be applied until the agent is able to restart.
Recommendations
For Cilium versions 1.14.0 through 1.14.7, update to version 1.14.18.
For Cilium versions 1.15.0 through 1.15.11, update to version 1.15.12.
For Cilium versions 1.16.0 through 1.16.4, update to version 1.16.5.
As a temporary workaround, consider restricting access to the DNS proxy until a patch is available.
Avoid using the DNS-based policy for new connections until the issue is resolved.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cilium
Suse