SCA: security update for volcano.sh/volcano (GHSA-hg79-fw4p-25p8)

high Tenable Self-Hosted Container Security Plugin ID 434673

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1,
1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service
or the extender plugin can cause denial of service of the scheduler. This is a privilege escalation,
because Volcano users may run their Elastic service and extender plugins in separate pods or nodes from
the scheduler. In the Kubernetes security model, node isolation is a security boundary, and as such an
attacker is able to cross that boundary in Volcano's case if they have compromised either the vulnerable
services or the pod/node in which they are deployed. The scheduler will become unavailable to other users
and workloads in the cluster. The scheduler will either crash with an unrecoverable OOM panic or freeze
while consuming excessive amounts of memory. This issue has been patched in versions 1.11.2, 1.10.2,
1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2. (CVE-2025-32777)

See Also

https://github.com/advisories/GHSA-hg79-fw4p-25p8

Plugin Details

Severity: High

ID: 434673

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 8/19/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2025-32777

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.2

Threat Score: 4.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/30/2025

Vulnerability Publication Date: 4/30/2025

Reference Information

CVE: CVE-2025-32777

cwe: CWE-770