Bug 2354604 (CVE-2025-30162) - CVE-2025-30162 cilium: East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Summary: CVE-2025-30162 cilium: East-west traffic not subject to egress policy enforce...
Keywords:
Status: NEW
Alias: CVE-2025-30162
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2354685 2354686 2354687 2354689 2354690 2354691 2354692 2354693 2354695 2354697 2354698 2354699 2354700 2354701 2354703 2354704 2354705 2354706 2354707 2354709 2354710 2354711 2354680 2354681 2354682 2354683 2354684 2354688 2354694 2354696 2354702 2354708
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-03-24 19:01 UTC by OSIDB Bzimport
Modified: 2025-03-25 03:33 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-03-24 19:01:11 UTC
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces, egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed. LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue. This issue affects: Cilium v1.15 between v1.15.0 and v1.15.14 inclusive, v1.16 between v1.16.0 and v1.16.7 inclusive, and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.15.15, v1.16.8, and v1.17.2. A Clusterwide Cilium Network Policy can be used to work around this issue for users who are unable to upgrade.


Note You need to log in before you can comment on or make changes to this bug.