Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass. This issue has been patched in Cilium v1.14.14 and v1.15.8 As the underlying issue depends on a race condition, users unable to upgrade can restart the Cilium agent on affected nodes until the affected policies are confirmed to be working as expected.
History

Fri, 27 Sep 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Cilium
Cilium cilium
CPEs cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
Vendors & Products Cilium
Cilium cilium

Mon, 19 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Aug 2024 20:45:00 +0000

Type Values Removed Values Added
Description Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass. This issue has been patched in Cilium v1.14.14 and v1.15.8 As the underlying issue depends on a race condition, users unable to upgrade can restart the Cilium agent on affected nodes until the affected policies are confirmed to be working as expected.
Title Cilium agent's race condition may lead to policy bypass for Host Firewall policy
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-15T20:36:29.463Z

Updated: 2024-08-19T19:23:37.503Z

Reserved: 2024-08-02T14:13:04.618Z

Link: CVE-2024-42488

cve-icon Vulnrichment

Updated: 2024-08-19T19:23:31.662Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-15T21:15:17.270

Modified: 2024-09-27T18:49:05.410

Link: CVE-2024-42488

cve-icon Redhat

No data.