CVE-2025-4563

Name
CVE-2025-4563
Description
A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
mailing-list https://groups.google.com/g/kubernetes-security-announce/c/Zv84LMRuvMQ
issue-tracking https://github.com/kubernetes/kubernetes/issues/132151

Match rules

CPE URI Source package Min version Max version
kubernetes == v1.32.0 - v1.32.5 == v1.32.0 - v1.32.5
kubernetes == v1.33.0 - v1.33.1 == v1.33.0 - v1.33.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status