MEDIUM6.7
GHSA-4x4m-3c2p-qppc
Kubernetes Nodes can delete themselves by adding an OwnerReference
Quick fix
GHSA-4x4m-3c2p-qppc — k8s.io/kubernetes: upgrade to the fixed version with the command below.
go get k8s.io/kubernetes@v1.31.12Details
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/k8s.io/kubernetes
Introduced in:
1.32.0-alpha.0Fixed in: 1.32.8Fix
go get k8s.io/kubernetes@v1.32.8Go/k8s.io/kubernetes
Introduced in:
1.33.0-alpha.0Fixed in: 1.33.4Fix
go get k8s.io/kubernetes@v1.33.4References
- https://nvd.nist.gov/vuln/detail/CVE-2025-5187[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/133471[WEB]
- https://github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f[WEB]
- https://github.com/kubernetes/kubernetes[PACKAGE]
- https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE[WEB]