CVE-2025-32793
MEDIUM4.0EPSS 0.01%In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
Description
### Impact When using [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg) in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium. ### Patches This issue has been patched in https://github.com/cilium/cilium/pull/38592. This issue affects: - Cilium v1.15 between v1.15.0 and v1.15.15 inclusive - Cilium v1.16 between v1.16.0 and v1.16.8 inclusive - Cilium v1.17 between v1.17.0 and v1.17.2 inclusive This issue is fixed in: - Cilium v1.15.16 - Cilium v1.16.9 - Cilium v1.17.3 ### Workarounds There is no workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @gandro and @pippolo84 for reporting this issue and to @julianwiedmann for the patch. ### For more information If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and your report will be treated as top priority.
Affected packages (5)
- Bitnami/cilium>= 1.13.0, < 1.17.3
- Bitnami/cilium-operator>= 1.13.0, < 1.17.3
- Bitnami/hubble-relay>= 1.13.0, < 1.17.3
- Go/github.com/cilium/cilium>= 1.13.0, < 1.15.16
- Go/github.com/cilium/cilium>= 1.13.0, < 1.15.16, >= 1.16.0, < 1.16.9, >= 1.17.0, < 1.17.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.0 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N |