github.com/talos-systems/talos
Talos Linux is a modern Linux distribution built for Kubernetes.
Activity
- Latest release
- Jun 22, 2026
- Total releases
- 50
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Stars
- 10.9k
Details
- First release
- Jan 02, 2019
| Version | Released | |
|---|---|---|
v1.13.5
patch
|
v1.13.5
patch
Dependencies (165)
+ 157 more |
|
v1.13.0
minor
|
v1.13.0
minor
Dependencies (164)
+ 156 more |
|
v1.12.7
minor
|
v1.12.7
minor
Dependencies (160)
+ 152 more |
|
v1.11.5
patch
|
v1.11.5
patch
Dependencies (161)
+ 153 more |
|
v1.11.1
minor
|
v1.11.1
minor
Dependencies (161)
+ 153 more |
|
v1.10.3
minor
|
v1.10.3
minor
Dependencies (159)
+ 151 more |
|
v1.9.5
minor
|
v1.9.5
minor
Dependencies (159)
+ 151 more |
|
v1.8.4
patch
|
v1.8.4
patch
Dependencies (154)
+ 146 more |
|
v1.9.0-alpha.0
pre
|
v1.9.0-alpha.0
pre
Dependencies (154)
+ 146 more |
|
v1.8.1
minor
|
v1.8.1
minor
Dependencies (153)
+ 145 more |
|
v1.8.0-beta.0
pre
|
v1.8.0-beta.0
pre
Dependencies (152)
+ 144 more |
|
v1.7.6
patch
|
v1.7.6
patch
Dependencies (147)
+ 139 more |
|
v1.7.4
minor
|
v1.7.4
minor
Dependencies (147)
+ 139 more |
|
v1.6.7
patch
|
v1.6.7
patch
Dependencies (140)
+ 132 more |
|
v1.7.0-alpha.1
pre
|
v1.7.0-alpha.1
pre
Dependencies (142)
+ 134 more |
|
v1.6.2
minor
|
v1.6.2
minor
Dependencies (136)
+ 128 more |
|
v1.6.0-alpha.1
pre
|
v1.6.0-alpha.1
pre
Dependencies (128)
+ 120 more |
|
v1.4.8
patch
|
v1.4.8
patch
Dependencies (120)
+ 112 more |
|
v1.4.7
minor
|
v1.4.7
minor
Dependencies (120)
+ 112 more |
|
v1.3.7
minor
|
v1.3.7
minor
Dependencies (118)
+ 110 more |
|
v1.3.0-beta.2
pre
|
v1.3.0-beta.2
pre
Dependencies (118)
+ 110 more |
|
v1.2.0-alpha.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v1.2.0-alpha.0
pre
Dependencies (111)
+ 103 more |
|
v1.1.0
minor
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v1.1.0
minor
Dependencies (111)
+ 103 more |
|
v1.0.1
major
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v1.0.1
major
Dependencies (106)
+ 98 more |
|
v0.14.3
minor
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.14.3
minor
Dependencies (98)
+ 90 more |
|
v0.15.0-alpha.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.15.0-alpha.0
pre
Dependencies (100)
+ 92 more |
|
v0.14.0-alpha.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.14.0-alpha.0
pre
Dependencies (95)
+ 87 more |
|
v0.13.0-alpha.1
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.13.0-alpha.1
pre
Dependencies (91)
+ 83 more |
|
v0.12.1
minor
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.12.1
minor
Dependencies (85)
+ 77 more |
|
v0.11.0-beta.1
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.11.0-beta.1
pre
Dependencies (85)
+ 77 more |
|
v0.11.0-alpha.1
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.11.0-alpha.1
pre
Dependencies (85)
+ 77 more |
|
v0.11.0-alpha.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.11.0-alpha.0
pre
Dependencies (85)
+ 77 more |
|
v0.9.0-alpha.2
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.9.0-alpha.2
pre
Dependencies (72)
+ 64 more |
|
v0.7.0-alpha.8
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.7.0-alpha.8
pre
Dependencies (67)
+ 59 more |
|
v0.7.0-alpha.2
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.7.0-alpha.2
pre
Dependencies (66)
+ 58 more |
|
v0.5.0-beta.1
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.5.0-beta.1
pre
Dependencies (59)
+ 51 more |
|
v0.5.0-beta.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.5.0-beta.0
pre
Dependencies (59)
+ 51 more |
|
v0.5.0-alpha.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.5.0-alpha.0
pre
Dependencies (59)
+ 51 more |
|
v0.4.0-beta.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.4.0-beta.0
pre
Dependencies (59)
+ 51 more |
|
v0.4.0-alpha.7
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.4.0-alpha.7
pre
Dependencies (59)
+ 51 more |
|
v0.3.2
minor
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.3.2
minor
Dependencies (48)
+ 40 more |
|
v0.3.0-beta.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.3.0-beta.0
pre
Dependencies (46)
+ 38 more |
|
v0.3.0-alpha.7
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.3.0-alpha.7
pre
Dependencies (42)
+ 34 more |
|
v0.2.0
initial
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.2.0
initial
Dependencies (44)
+ 36 more |
|
v0.2.0-rc.0
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.2.0-rc.0
pre
Dependencies (44)
+ 36 more |
|
v0.1.0-beta.1
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.1.0-beta.1
pre
Dependencies (38)
+ 30 more |
|
v0.1.0-alpha.26
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.1.0-alpha.26
pre
Dependencies (39)
+ 31 more |
|
v0.1.0-alpha.21
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.1.0-alpha.21
pre
Dependencies (25)
+ 17 more |
|
v0.1.0-alpha.17
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.1.0-alpha.17
pre
Dependencies (19)
+ 11 more |
|
v0.1.0-alpha.15
pre
2 CVEs
CVE-2022-36103
GO-2022-0995
GHSA-7hgc-php5-77qq
Aug 21, 2024
Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Talos worker join token can be used to get elevated access level to the Talos API in github.com/talos-systems/talos Fixed in
1.2.2
References Updated Mar 03, 2026 · Source: OSV.dev
GHSA-34vw-m4rh-r36p
Sep 16, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
ImpactA race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. PatchesThe fix has been backported to 5.15.64 version of the upstream Linux kernel (5.15 is the upstream Kernel long term version Talos ships with). Talos >= v1.2.0 is shipped with Linux Kernel 5.15.64 fixing the above issue. Kubernetes workloads running in Talos are not affected since user namespaces are disabled in Talos kernel config. So an unprivileged user cannot obtain CAP_NET_ADMIN by unsharing. However untrusted workloads that run with privileged: true or having NET_ADMIN capability poses a risk. WorkaroundsAudit kubernetes workloads running in the cluster with privileged: true set or having NET_ADMIN capability and assess the threat vector. References
For more information
Fixed in
1.2.0
References Updated Sep 16, 2022 · Source: OSV.dev |
v0.1.0-alpha.15
pre
Dependencies (19)
+ 11 more |