8.2
CWE
770
Advisory Published
CVE Published
Updated

CVE-2025-32777: Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin

First published: Wed Apr 30 2025(Updated: )

### Impact This issue allows an attacker who has compromised either the Elastic service or the extender plugin to cause denial of service of the scheduler. This is a privilege escalation, because Volcano users may run their Elastic service and extender plugins in separate pods or nodes from the scheduler. In the Kubernetes security model, node isolation is a security boundary, and as such an attacker is able to cross that boundary in Volcano's case if they have compromised either the vulnerable services or the pod/node in which they are deployed. The scheduler will become unavailable to other users and workloads in the cluster. The scheduler will either crash with an unrecoverable OOM panic or freeze while consuming excessive amounts of memory. ### Workarounds No

Credit: security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
go/volcano.sh/volcano>=1.12.0-alpha.0<1.12.0-alpha.2
1.12.0-alpha.2
go/volcano.sh/volcano>=1.11.0<1.11.2
1.11.2
go/volcano.sh/volcano>=1.11.0-network-topology-preview.0<1.11.0-network-topology-preview.3
1.11.0-network-topology-preview.3
go/volcano.sh/volcano>=1.10.0-alpha.0<1.10.2
1.10.2
go/volcano.sh/volcano<1.9.1
1.9.1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2025-32777?

    CVE-2025-32777 is classified as a privilege escalation vulnerability that can lead to denial of service.

  • How do I fix CVE-2025-32777?

    To fix CVE-2025-32777, upgrade to Volcano version 1.12.0-alpha.2, 1.11.2, 1.11.0-network-topology-preview.3, 1.10.2, or 1.9.1 as applicable.

  • What vulnerabilities does CVE-2025-32777 affect?

    CVE-2025-32777 affects specific versions of the Volcano software including versions below 1.12.0-alpha.2.

  • What are the potential impacts of CVE-2025-32777?

    The potential impacts of CVE-2025-32777 include service disruption and privilege escalation within the scheduler.

  • Who is impacted by CVE-2025-32777?

    Users of the Volcano software running Elastic services or extender plugins in separate pods or nodes may be impacted by CVE-2025-32777.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203