Catalog / Kubernetes

1.31.12

Kubernetes v1.31.12

1.2 years agosecurityfixedchangedOriginal notes

Changelog since v1.31.11

Important Security Information

This release contains changes that address the following vulnerabilities:

CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference

A vulnerability exists in the NodeRestriction admission controller where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection. By default, node users are authorized for create and patch requests but not delete requests against their node object. Since the NodeRestriction admission controller does not prevent patching OwnerReferences, a compromised node could leverage this vulnerability to delete and then recreate its node object with modified taints or labels.

Affected Versions:

  • kube-apiserver v1.31.0 - v1.31.11
  • kube-apiserver v1.32.0 - v1.32.7
  • kube-apiserver v1.33.0 - v1.33.3

Fixed Versions:

  • kube-apiserver v1.31.12
  • kube-apiserver v1.32.8
  • kube-apiserver v1.33.4

This vulnerability was reported by Paul Viossat.

CVSS Rating: Medium (6.7) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Changes by Kind

Feature

  • Kubernetes is now built using Go 1.23.11 (#132899, @cpanato) [SIG Release and Testing]

Bug or Regression

  • Changed the node restrictions to disallow the node to change it's ownerReferences. (#133470, @natherz97) [SIG Auth]

Dependencies

Added

Nothing has changed.

Changed

Nothing has changed.

Removed

Nothing has changed.