aws / aws/eks-distro

Security [kubelet version 1.34] is compiled with github.com/opencontainers/selinux <1.13.0 - CVE-2025-52881

Open
#4,690 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
1.5k
Forks
198
Avg merge
10h 46m
Merged PRs (30d)
28

Description

We verified that kubelet in EKS AMIs (1.34) is compiled with
github.com/opencontainers/selinux <1.13.0, which is vulnerable to CVE-2025-52881.

Since kubelet is statically compiled, this cannot be remediated at the OS or AMI level.

Can you confirm:
- which upcoming EKS-Distro release will include go-selinux ≥1.13.0?
- whether a rebuild is planned?

Contributor guide

Open the contributing guide

Research direction

Start by examining how kubelet is built into the EKS AMIs and where the github.com/opencontainers/selinux dependency version is selected. Check the go-selinux version against CVE-2025-52881 and identify the upcoming EKS-Distro release or rebuild that contains version 1.13.0 or later.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go, kubernetes
Domain
infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.