CVE-2025-0426: [kubernetes] CVE-2025-0426: Node Denial of Service via kubelet Checkpoint API
A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/k8s.io/kubernetesto a version that resolves this vulnerability.Fixed in 1.29.14 - Upgrade
Upgrade
go/k8s.io/kubernetesto a version that resolves this vulnerability.Fixed in 1.30.10 - Upgrade
Upgrade
go/k8s.io/kubernetesto a version that resolves this vulnerability.Fixed in 1.31.6 - Upgrade
Upgrade
go/k8s.io/kubernetesto a version that resolves this vulnerability.Fixed in 1.32.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0426?
CVE-2025-0426 has been classified as a Denial of Service vulnerability.
How do I fix CVE-2025-0426?
To remediate CVE-2025-0426, upgrade Kubernetes to version 1.29.14 or later, or to specific patched versions like 1.30.10, 1.31.6, or 1.32.2.
What causes CVE-2025-0426?
CVE-2025-0426 is caused by an unauthenticated large number of container checkpoint requests sent to the kubelet read-only HTTP endpoint.
Which versions of Kubernetes are affected by CVE-2025-0426?
CVE-2025-0426 affects Kubernetes versions prior to 1.29.14 and those between 1.30.0 and 1.30.10, 1.31.0 and 1.31.6, and 1.32.0 and 1.32.2.
Can CVE-2025-0426 lead to data loss?
While CVE-2025-0426 itself causes a Denial of Service, it may lead to unavailability of services rather than direct data loss.