CVE-2025-4563: Nodes can bypass dynamic resource allocation authorization checks

Published Jun 19, 2025
·
Updated

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.

Affected Software

3 affected componentsFixes available
Kubernetes kubernetes
go/k8s.io/kubernetes>=1.33.0<=1.33.1
1.33.2
go/k8s.io/kubernetes>=1.32.0<=1.32.5
1.32.6

Remediation

Information

To mitigate this vulnerability, upgrade Kubernetes: https://kubernetes.io/docs/tasks/administer-cluster/cluster-upgrade/

Event History

Jun 23, 2025
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-4563?

CVE-2025-4563 has a high severity due to potential unauthorized access to dynamic resource allocation.

2

How do I fix CVE-2025-4563?

To fix CVE-2025-4563, ensure that the DynamicResourceAllocation feature gate is properly configured and validate node authorization rules.

3

Which versions of Kubernetes are affected by CVE-2025-4563?

CVE-2025-4563 affects certain versions of Kubernetes where the NodeRestriction admission controller is improperly configured.

4

What is the impact of CVE-2025-4563?

The impact of CVE-2025-4563 includes the risk of nodes bypassing resource allocation authorization checks, potentially leading to resource misuse.

5

Is there a workaround for CVE-2025-4563 until a patch is available?

A recommended workaround for CVE-2025-4563 is to disable the DynamicResourceAllocation feature gate until an official patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203