Bug 2354604 (CVE-2025-30162)
Summary: | CVE-2025-30162 cilium: East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | adudiak, alcohan, fdeutsch, gparvin, jwendell, kshier, mwringe, njean, omaciel, oramraz, owatkins, pahickey, rcernich, rhaigner, smullick, stcannon, stirabos, thason, yguenane |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | --- | |
Doc Text: |
A flaw was found in cilium package. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces, egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2354697, 2354698, 2354699, 2354700, 2354703, 2354704, 2354705, 2354706, 2354707, 2354711, 2354680, 2354681, 2354682, 2354683, 2354684, 2354685, 2354686, 2354687, 2354688, 2354689, 2354690, 2354691, 2354692, 2354693, 2354694, 2354695, 2354696, 2354701, 2354702, 2354708, 2354709, 2354710 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2025-03-24 19:01:11 UTC
|