Cilium Wireguard Encryption Race Condition Vulnerability

Vulnerability

A vulnerability exists in Cilium versions 1.15.0 prior to 1.15.16, 1.16.0 prior to 1.16.9, and 1.17.0 prior to 1.17.3, when Wireguard transparent encryption is used. Due to a race condition in traffic processing, packets from terminating endpoints can leave the source node unencrypted. This issue arises for packets where the source endpoint has been dismantled before the packet reaches the network interface, causing the packet to bypass encryption.

Impact

Exploitation of this vulnerability can lead to unencrypted packet transmission from terminating endpoints in a Cilium cluster using Wireguard encryption, potentially exposing sensitive data.

Remediation

Users can upgrade to Cilium versions 1.15.16, 1.16.9, or 1.17.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.6
exploitability
6.5
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.