Insecure IPsec transport encryption in Cilium
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective. In particular, Cilium is vulnerable to chosen plaintext, key recovery, replay attacks by a man-in-the-middle attacker. These attacks are possible due to an ESP sequence number collision when multiple nodes are configured with the same key. Fixed versions of Cilium use unique keys for each IPsec tunnel established between nodes, resolving all of the above attacks. This vulnerability is fixed in 1.13.13, 1.14.9, and 1.15.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/cilium/ciliumGo | >= 1.4.0, < 1.13.14 | 1.13.14 |
github.com/cilium/ciliumGo | >= 1.14.0, < 1.14.9 | 1.14.9 |
github.com/cilium/ciliumGo | >= 1.15.0, < 1.15.3 | 1.15.3 |
Affected products
27- osv-coords26 versionspkg:apk/chainguard/cilium-1.14pkg:apk/chainguard/cilium-1.14-clustermesh-apiserverpkg:apk/chainguard/cilium-1.14-container-initpkg:apk/chainguard/cilium-1.14-container-init-compatpkg:apk/chainguard/cilium-1.14-hubble-relaypkg:apk/chainguard/cilium-1.14-iptablespkg:apk/chainguard/cilium-1.14-operator-awspkg:apk/chainguard/cilium-1.14-operator-genericpkg:apk/chainguard/hubble-uipkg:apk/chainguard/hubble-ui-backendpkg:apk/wolfi/cilium-1.14pkg:apk/wolfi/cilium-1.14-container-initpkg:apk/wolfi/cilium-1.14-container-init-compatpkg:apk/wolfi/cilium-1.14-hubble-relaypkg:apk/wolfi/cilium-1.14-iptablespkg:apk/wolfi/cilium-1.14-operator-genericpkg:apk/wolfi/hubble-uipkg:apk/wolfi/hubble-ui-backendpkg:bitnami/ciliumpkg:bitnami/cilium-operatorpkg:bitnami/cilium-proxypkg:bitnami/hubblepkg:bitnami/hubble-relaypkg:bitnami/hubble-uipkg:bitnami/hubble-ui-backendpkg:golang/github.com/cilium/cilium
< 1.14.19-r34+ 25 more
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 0.13.0-r6
- (no CPE)range: < 0.13.0-r6
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 1.14.19-r34
- (no CPE)range: < 0.13.0-r6
- (no CPE)range: < 0.13.0-r6
- (no CPE)range: >= 1.14.0, < 1.14.9
- (no CPE)range: >= 1.14.0, < 1.14.9
- (no CPE)range: >= 1.4.0, < 1.13.14
- (no CPE)range: >= 1.4.0, < 1.13.14
- (no CPE)range: >= 1.14.0, < 1.14.9
- (no CPE)range: >= 1.4.0, < 1.13.14
- (no CPE)range: >= 1.4.0, < 1.13.14
- (no CPE)range: >= 1.4.0, < 1.13.14
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-pwqm-x5x6-5586ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-28860ghsaADVISORY
- docs.cilium.io/en/stable/security/network/encryption-ipsecghsax_refsource_MISCWEB
- github.com/cilium/cilium/commit/311fbce5280491cddceab178d83b06fa23688c72ghsax_refsource_MISCWEB
- github.com/cilium/cilium/commit/a1742b478306fa256cd27df1039dfae0537b4149ghsax_refsource_MISCWEB
- github.com/cilium/cilium/commit/a652c123331852cca90c74202f993d4170fd37faghsax_refsource_MISCWEB
- github.com/cilium/cilium/security/advisories/GHSA-pwqm-x5x6-5586ghsax_refsource_CONFIRMWEB
- pkg.go.dev/vuln/GO-2024-2666ghsaWEB
News mentions
0No linked articles in our index yet.