1.32.6
Kubernetes v1.32.6
Changelog since v1.32.5
Important Security Information
This release contains changes that address the following vulnerabilities:
CVE-2025-4563: Nodes can bypass dynamic resource allocation authorization checks
A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.
Affected Versions:
- kube-apiserver v1.32.0 - v1.32.5
- kube-apiserver v1.33.0 - v1.33.1
Fixed Versions:
- kube-apiserver v1.32.6
- kube-apiserver v1.33.2
This vulnerability was reported by amitschendel.
CVSS Rating: Low (2.7) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Changes by Kind
Feature
- Kubernetes is now built using Go 1.23.10 (#132225, @cpanato) [SIG Release and Testing]
- Kubernetes is now built using Go 1.23.9 (#131936, @cpanato) [SIG Release and Testing]
Bug or Regression
- Do not expand volume on the node, if controller expansion is finished (#132010, @gnufied) [SIG Storage]
- Do not log error event when waiting for expansion on the kubelet (#132099, @gnufied) [SIG Storage]
- Fixes an issue where Windows kube-proxy's ModifyLoadBalancer API updates did not match HNS state in version 15.4. ModifyLoadBalancer policy is supported from Kubernetes 1.31+. (#131652, @princepereira) [SIG Windows]
- Kubelet: close a loophole where static pods could reference arbitrary ResourceClaims. The pods created by the kubelet then don't run due to a sanity check, but such references shouldn't be allowed regardless. (#131875, @pohly) [SIG Apps, Auth and Node]
- Removed a warning around Linux user namespaces and kernel version. If the feature gate
UserNamespacesSupportwas enabled, the kubelet previously warned when detecting a Linux kernel version earlier than 6.3.0. User namespace support on Linux typically does still need kernel 6.3 or newer, but it can work in older kernels too. (#131784, @rata) [SIG Node]
Other (Cleanup or Flake)
- Improve error message when a pod with user namespaces is created and the runtime doesn't support user namespaces. (#131782, @rata) [SIG Node]
Dependencies
Added
Nothing has changed.
Changed
- github.com/Microsoft/hnslib: v0.0.8 → v0.1.1
Removed
Nothing has changed.