CVE-2024-7598

Publication date 20 March 2025

Last updated 11 July 2025


Ubuntu priority

Cvss 3 Severity Score

3.1 · Low

Score breakdown

Description

A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for network policies to be deleted before the pods that they protect. This can lead to a brief period in which the pods are running, but network policies that should apply to connections to and from the pods are not enforced.

Read the notes from the security team

Status

Package Ubuntu Release Status
kubernetes 25.04 plucky Not in release
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble
Not affected
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected

Notes


leosilva

kubernates is in fact a kubernetes installer that calls snap, not the package it self.

Severity score breakdown

Parameter Value
Base score 3.1 · Low
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Access our resources on patching vulnerabilities