/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-wgc4-3v22-6fc6

Published

Last updated

https://images.chainguard.dev/security/CGA-wgc4-3v22-6fc6
Package

kubernetes-1.28

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-0426
  • GHSA-jgfp-53c3-624w

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-0426

Updates

Status

Fix not planned

Impact

Kubernetes 1.28 has reached its end of life (EOL). To resolve the issue with the newer version of the Kubernetes package, upstream maintainers would need to provide a patch for 1.28. In the meantime, you can mitigate the problem by disabling the ContainerCheckpoint feature gate in your kubelet configuration, turning off the kubelet read-only port, and restricting access to the kubelet API. Alternatively, upgrading to a fixed version, which enforces authentication for the kubelet Checkpoint API, will resolve the issue. For further details, please refer to this GitHub issue: https://github.com/kubernetes/kubernetes/issues/130016.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing