1.33.4
Kubernetes v1.33.4
Changelog since v1.33.3
Important Security Information
This release contains changes that address the following vulnerabilities:
CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference
A vulnerability exists in the NodeRestriction admission controller where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection. By default, node users are authorized for create and patch requests but not delete requests against their node object. Since the NodeRestriction admission controller does not prevent patching OwnerReferences, a compromised node could leverage this vulnerability to delete and then recreate its node object with modified taints or labels.
Affected Versions:
- kube-apiserver v1.31.0 - v1.31.11
- kube-apiserver v1.32.0 - v1.32.7
- kube-apiserver v1.33.0 - v1.33.3
Fixed Versions:
- kube-apiserver v1.31.12
- kube-apiserver v1.32.8
- kube-apiserver v1.33.4
This vulnerability was reported by Paul Viossat.
CVSS Rating: Medium (6.7) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Changes by Kind
API Change
- Fixes a 1.33 regression that can cause a nil panic in kube-scheduler when aggregating resource requests across container's spec and status. (#133285, @yue9944882) [SIG Node and Scheduling]
Feature
Bug or Regression
- Changed the node restrictions to disallow the node to change it's ownerReferences. (#133468, @natherz97) [SIG Auth]
Dependencies
Added
Nothing has changed.
Changed
Nothing has changed.
Removed
Nothing has changed.