Skip to content

Add security bulletin for CVE-2025-4563 #258

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions articles/aks/security-bulletins/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,39 @@ These updates cover security information related to the following AKS components
- Azure Kubernetes Service Node Image (AKS Node Image)
- Azure Kubernetes Service Addons (AKS add-ons)

---

## AKS-2025-008 Nodes can bypass dynamic resource allocation authorization checks

**Published Date**: June 19, 2025

### Description

A security issue has been identified in Kubernetes related to the DynamicResourceAllocation feature. When enabled, this feature may allow users with pod creation privileges to escalate privileges or access unauthorized resources on the node.

This vulnerability only affects clusters where the DynamicResourceAllocation feature is explicitly enabled.

### References

- [CVE-2025-4563](https://github.com/kubernetes/kubernetes/issues/132151)

### Affected Components
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@riyac12 is this not the title for Affected Components?


#### [**AKS Cluster**](#tab/aks-cluster)

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still need the title for Affected Components

**Affected Versions**

- None

**Resolutions**

- AKS does not support or enable the `DynamicResourceAllocation` feature in any supported version. Therefore, AKS clusters are not vulnerable to this issue.
- Although AKS is not affected, the upstream fix will be included in the following AKS cluster versions:
  - AKS 1.32.6
  - AKS 1.33.2
- No customer action is required unless you are preparing for future use of this feature. Customers are encouraged to upgrade to the fixed versions once available.


---

## AKS-2025-007 Important Security Update for Kubernetes Nginx Ingress Controller
Expand Down