CVE-2024-42488
published 2024-08-15CVE-2024-42488: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium…
PriorityP335medium6.8CVSS 3.1
AVNACHPRNUINSCCHINAN
EPSS
0.50%
41.8th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass. This issue has been patched in Cilium v1.14.14 and v1.15.8 As the underlying issue depends on a race condition, users unable to upgrade can restart the Cilium agent on affected nodes until the affected policies are confirmed to be working as expected.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | < 1.14.14 | 1.14.14 |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.15.0 < 1.15.8 | 1.15.8 |
| github.com | cilium_cilium | >= 0 < 1.14.14 | 1.14.14 |
| github.com | cilium_cilium | >= 1.15.0 < 1.15.8 | 1.15.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Policy bypass for Host Firewall policy due to race condition in Cilium agent in github.com/cilium/cilium
osv·2024-08-16
CVE-2024-42488 Policy bypass for Host Firewall policy due to race condition in Cilium agent in github.com/cilium/cilium
Policy bypass for Host Firewall policy due to race condition in Cilium agent in github.com/cilium/cilium
Policy bypass for Host Firewall policy due to race condition in Cilium agent in github.com/cilium/cilium
GHSA
Policy bypass for Host Firewall policy due to race condition in Cilium agent
ghsa·2024-08-15
CVE-2024-42488 [MEDIUM] CWE-362 Policy bypass for Host Firewall policy due to race condition in Cilium agent
Policy bypass for Host Firewall policy due to race condition in Cilium agent
### Impact
A race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass.
### Patches
This issue was fixed in https://github.com/cilium/cilium/pull/33511.
This issue affects:
- All versions of Cilium before v1.14.14
- Cilium v1.15 between v1.15.0 and v1.15.7 inclusive
This issue has been patched in:
- Cilium v1.14.14
- Cilium v1.15.8
### Workarounds
As the underlying issue depends on a race condition, users unable to upgrade can restart the Cilium agent on affected nodes until the affected policies are confirmed to be work
OSV
Policy bypass for Host Firewall policy due to race condition in Cilium agent
osv·2024-08-15
CVE-2024-42488 [MEDIUM] Policy bypass for Host Firewall policy due to race condition in Cilium agent
Policy bypass for Host Firewall policy due to race condition in Cilium agent
### Impact
A race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass.
### Patches
This issue was fixed in https://github.com/cilium/cilium/pull/33511.
This issue affects:
- All versions of Cilium before v1.14.14
- Cilium v1.15 between v1.15.0 and v1.15.7 inclusive
This issue has been patched in:
- Cilium v1.14.14
- Cilium v1.15.8
### Workarounds
As the underlying issue depends on a race condition, users unable to upgrade can restart the Cilium agent on affected nodes until the affected policies are confirmed to be work
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-15
Published