Protection mechanism failure in Cilium - CVE-2025-64715

 

Protection mechanism failure in Cilium - CVE-2025-64715

Published: November 28, 2025


Vulnerability identifier: #VU118837
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-64715
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to an error in CiliumNetworkPolicy implementation. If the egress.toGroups.aws.securityGroupsIds references AWS security group IDs that do not exist or are not attached to any network interface, the toCIDRset section of the derived policy is not generated. As a result the outbound traffic is allowed to more destinations than originally intended.


Affected software

Cilium

How to mitigate CVE-2025-64715

Install updates from vendor's website.

Cilium - addressed in versions 1.16.17, 1.17.10, 1.18.4

External References

Related Security Bulletins