Record summary

CVE-2025-0426 has a selected CVSS score of 6.2 (medium).

Description

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 13, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List1.32.0 to ≤ 1.32.1affected
1.31.0 to ≤ 1.31.5affected
1.30.0 to ≤ 1.30.9affected
1.32.2unaffected
1.31.6unaffected
1.30.10unaffected
GitHub Advisory1.32.0 to < 1.32.2 · Fixed in 1.32.2affected
1.31.0 to < 1.31.6 · Fixed in 1.31.6affected
1.30.0 to < 1.30.10 · Fixed in 1.30.10affected
Before 1.29.14 · Fixed in 1.29.14affected

References

6