6.5

CVE-2025-43915

In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4, and 2.17.0–2.17.1, resource exhaustion can occur for Linkerd proxy metrics.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linkerd ≫ Buoyant SwEdition enterprise SwPlatform linkerd Version >= 2.13.0 <= 2.13.7
Linkerd ≫ Buoyant SwEdition enterprise SwPlatform linkerd Version >= 2.14.0 <= 2.14.10
Linkerd ≫ Buoyant SwEdition enterprise SwPlatform linkerd Version >= 2.15.0 <= 2.15.7
Linkerd ≫ Buoyant SwEdition enterprise SwPlatform linkerd Version >= 2.16.0 < 2.16.5
Linkerd ≫ Buoyant SwEdition enterprise SwPlatform linkerd Version >= 2.17.0 < 2.17.2
Linkerd ≫ Linkerd SwEdition edge SwPlatform kubernetes Version < 25.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.24
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.5 2.2 4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://www.buoyant.io/resources
Product
https://docs.buoyant.io/security/advisories/2025-01/
Vendor Advisory