Database/Container, Kubernetes & orchestration
Kubernetes (kubelet): Unauthenticated node DoS through the kubelet checkpoint API filling node disk
CVSS 6.2CVE-2025-0426Container, Kubernetes & orchestrationcurated
Impact
Unauthenticated node DoS through the kubelet checkpoint API filling node disk
Who can reach it
Any pod on the cluster network reaching the kubelet port
What to do
Rolling kubelet upgrade with node drain; disable the ContainerCheckpoint feature gate
References
Related entries
- Kubernetes (kubelet): Incorrect permissions on Windows container log directories allow privilege escalationCVE-2024-5321 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Command injection on Windows nodes via the nodes/*/logs/query APICVE-2024-9042 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Pod writes to its own /etc/hosts unaccounted for in evictionCVE-2020-8557 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Container restart runs as uid 0 despite mustRunAsNonRootCVE-2019-11245 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Kubelet API DoS, including via the unauthenticated read-only portCVE-2020-8551 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Pods with an empty localhost seccomp profile field silently bypass seccomp enforcementCVE-2023-2431 · Kubernetes (kubelet)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.