CVE-2025-4563

LOW

Kubernetes 1.32.0-1.32.5 and 1.33.0-1.33.1 - Privilege Escalation via NodeRestriction Bypass

Title source: llm
STIX 2.1

Description

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

References (2)

Core 2

Scores

CVSS v3 2.7
EPSS 0.0065
EPSS Percentile 46.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (3)
k8s.io/kubernetes 1.32.0 - 1.32.6Go
Kubernetes/Kubernetes v1.32.0 - v1.32.5
Kubernetes/Kubernetes v1.33.0 - v1.33.1
Published Jun 23, 2025
Tracked Since Feb 18, 2026