Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-23028— DoS in Cilium agent DNS proxy from crafted DNS responses

Quick assessment

Affected
cilium cilium
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cilium是Cilium开源的一个开源软件。用于提供和透明地保护应用程序工作负载(如应用程序容器或进程)之间的网络连接和负载平衡。 Cilium存在安全漏洞。攻击者利用该漏洞可以通过向集群外部的工作载荷发送特制的 DNS 响应来使 Cilium 代理崩溃。

CVSS 5.3 · Medium EPSS 0.43% · P36

Possible ATT&CK Techniques 1 AI

T1498.002 · Reflection Amplification
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-23028

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DoS in Cilium agent DNS proxy from crafted DNS responses
Source: CVE Program / CVE List V5
Vulnerability Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. In a Kubernetes cluster where Cilium is configured to proxy DNS traffic, an attacker can crash Cilium agents by sending a crafted DNS response to workloads from outside the cluster. For traffic that is allowed but without using DNS-based policy, the dataplane will continue to pass traffic as configured at the time of the DoS. For workloads that have DNS-based policy configured, existing connections may continue to operate, and new connections made without relying on DNS resolution may continue to be established, but new connections which rely on DNS resolution may be disrupted. Any configuration changes that affect the impacted agent may not be applied until the agent is able to restart. This issue is fixed in Cilium v1.14.18, v1.15.12, and v1.16.5. No known workarounds are available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5
Vulnerability Title
Cilium 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cilium是Cilium开源的一个开源软件。用于提供和透明地保护应用程序工作负载(如应用程序容器或进程)之间的网络连接和负载平衡。 Cilium存在安全漏洞。攻击者利用该漏洞可以通过向集群外部的工作载荷发送特制的 DNS 响应来使 Cilium 代理崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
cilium cilium >= 1.14.0, < 1.14.18 -

II. Public POCs for CVE-2025-23028

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-23028

请登录查看更多情报信息。

Patches & Fixes for CVE-2025-23028 (1)

Vendor Advisories for CVE-2025-23028 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-23028

No comments yet


Leave a comment