A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
https://github.com/advisories/GHSA-4x4m-3c2p-qppc
https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE