CVE-2025-32777 Details
Description
Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service or the extender plugin can cause denial of service of the scheduler. This is a privilege escalation, because Volcano users may run their Elastic service and extender plugins in separate pods or nodes from the scheduler. In the Kubernetes security model, node isolation is a security boundary, and as such an attacker is able to cross that boundary in Volcano's case if they have compromised either the vulnerable services or the pod/node in which they are deployed. The scheduler will become unavailable to other users and workloads in the cluster. The scheduler will either crash with an unrecoverable OOM panic or freeze while consuming excessive amounts of memory. This issue has been patched in versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2.
A denial-of-service vulnerability has been identified in Volcano, a Kubernetes-native batch scheduling system, affecting versions prior to 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2. The issue arises when an attacker compromises either the Elastic service or the extender plugin, potentially leading to a scheduler outage. This vulnerability also allows for privilege escalation, as Volcano users can operate their Elastic service and extender plugins in different pods or nodes from the scheduler. In Kubernetes, node isolation is a security boundary, and an attacker can exploit this vulnerability by compromising the affected services or the pod/node where they are deployed. The result is a scheduler that becomes unavailable to other users and workloads in the cluster, either crashing due to an unrecoverable out-of-memory panic or freezing while consuming excessive memory.
Users are advised to upgrade to Volcano versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, or 1.12.0-alpha.2. After upgrading, be aware that the pprof endpoint for the Volcano Scheduler is disabled by default. If this endpoint is needed for debugging or monitoring, it must be explicitly enabled post-upgrade.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 30, 2025CISA-ADP
Assessed May 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/volcano-sh/volcano/releases/tag/v1.10.2 | [email protected] | Release NotesVendor |
| https://github.com/volcano-sh/volcano/releases/tag/v1.11.0-network-topology-preview.3 | [email protected] | Release NotesVendor |
| https://github.com/volcano-sh/volcano/releases/tag/v1.11.2 | [email protected] | Release NotesVendor |
| https://github.com/volcano-sh/volcano/releases/tag/v1.12.0-alpha.2 | [email protected] | Release NotesVendor |
| https://github.com/volcano-sh/volcano/releases/tag/v1.9.1 | [email protected] | Release NotesVendor |
| https://github.com/volcano-sh/volcano/security/advisories/GHSA-hg79-fw4p-25p8 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| volcano-sh/volcano | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2025 | New CVE Received | [email protected] |
Volerion