Skip to content

Security [kubelet version 1.34] is compiled with github.com/opencontainers/selinux <1.13.0 - CVE-2025-52881 #4690

Description

@agomez-infoblox

We verified that kubelet in EKS AMIs (1.34) is compiled with
github.com/opencontainers/selinux <1.13.0, which is vulnerable to CVE-2025-52881.

Since kubelet is statically compiled, this cannot be remediated at the OS or AMI level.

Can you confirm:

  • which upcoming EKS-Distro release will include go-selinux ≥1.13.0?
  • whether a rebuild is planned?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions