Race Condition Vulnerability in Cilium Networking Solution by Isovalent
CVE-2025-32793

4MEDIUM

Key Information:

Vendor

Cilium

Status
Vendor
CVE Published:
21 April 2025

What is CVE-2025-32793?

Cilium, a networking and security solution developed by Isovalent, contains a race condition vulnerability impacting specific versions when utilizing Wireguard transparent encryption. Packets originating from a terminating endpoint can exit the source node unencrypted due to the way traffic is processed within the Cilium cluster. This vulnerability affects versions ranging from 1.15.0 to 1.17.2. The issue has been addressed in subsequent releases, specifically versions 1.15.16, 1.16.9, and 1.17.3, rendering earlier versions susceptible. Notably, no workarounds are available for this vulnerability.

Affected Version(s)

cilium >= v1.13.0, < v1.15.16 < v1.13.0, v1.15.16

cilium >= v1.16.0, < v1.16.9 < v1.16.0, v1.16.9

cilium >= v1.17.0, < v1.17.3 < v1.17.0, v1.17.3

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32793 : Race Condition Vulnerability in Cilium Networking Solution by Isovalent