CVE-2025-4563

EUVD-2025-18894
A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 51.15%
Debian logo
Debian Releases
Debian Product
Codename
kubernetes
bookworm
1.20.5+really1.20.2-1.1+deb12u1
fixed
forky
1.33.4+ds-1
fixed
sid
1.33.4+ds-1
fixed
trixie
1.32.3+ds-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kubernetes
focal
not-affected
jammy
not-affected
noble
not-affected
oracular
ignored
plucky
dne
Azure Linux logo
Azure Linux Releases
Azure Package
Release
kubernetes
Azure Linux 3.0
0:1.30.10-9.azl3
fixed