Kubernetes v1.32.8 is live!

17 views
Skip to first unread message

Marko Mudrinić

unread,
Aug 13, 2025, 3:57:19 PMAug 13
to d...@kubernetes.io, kubernete...@googlegroups.com
Kubernetes Community,

Kubernetes v1.32.8 has been built and pushed using Golang version 1.23.11.

The release notes have been updated in CHANGELOG-1.32.md, with a pointer to them on GitHub:


v1.32.8

Downloads for v1.32.8

Source Code

filenamesha512 hash
kubernetes.tar.gz7280ce77f6568dc381e9e588b1fc848677aae726309b839d25992be3febc22bc88cd41265e5135642e52f71936e8a2bea9858bd1507ba0cac6d3361ad658be0d
kubernetes-src.tar.gz57957cede85d72114aef1f32214036f584409c15845b94975baaefb6c1af8b36c351703cd8fee661e12b463f206205aa5ebbd9bdabc3417b76f46c0ed51a6db1

Client Binaries

filenamesha512 hash
kubernetes-client-darwin-amd64.tar.gzbc9c9577775912ed4fbe5e05fc884f0b4d6040d2f56f51da862a97772aa3077ca72fbbe054a73af481acd6a42c47db882aa94273d271017d3999ed39a526a842
kubernetes-client-darwin-arm64.tar.gze95f670af43b32dc3130edd3cd386fd90b7c64278d547fb0ae7af1f54e5e5571889eeaabf2ca2f1e823851ba29711336fc341ffe80a05dde5a80befc8fa1543c
kubernetes-client-linux-386.tar.gzd99d35c3802dbc42bd9ff95215fd69a1034f1d4000eeae95971d068994d3a90b9ac80e45f682b3a3bd5682f6209f7585e55460c884d1de6377bb6f38732a11d4
kubernetes-client-linux-amd64.tar.gz22a3a09327c2dcd05931188954e2a13c80d021026f494f5192808121d85003a87169f4e83cf3a340cd3c819c5629e874ea83bfa794602845fceafa8b8fb04464
kubernetes-client-linux-arm.tar.gz2d7e598e16256a32bc7d4ba283a9dbac4b23868d57c4e5853e32a4fa9b55d20dac364d799a157ed4f06133431b0f56d0ac3218ca9564b78dc65a6a0d455a86d2
kubernetes-client-linux-arm64.tar.gz938866e1d8f5c111cb7ffd93f61b90bd4a9bbd2004a66c3f762173c125abe4f9aa824e7d1ecf4073cddddf994a3ce1c316590964bdb1012ca9926f1c210f00e3
kubernetes-client-linux-ppc64le.tar.gzc70378583aa245927c0f439f3b3f1e1bbe6158502e35daa267054120d977a5f67ef703104aa3b7ec20e9a464bad758709f0a26e44a5e6aec309691b2be96dc40
kubernetes-client-linux-s390x.tar.gzeb11bd8c7a8d1bd2c34e2a7aa7b5c4dc46c9e1974e8b1fd62f65e7ec3026458e9ee1b649c20da4e4e4eb04cf394850880e09e3744367ff0cb3da7b1653db1ccb
kubernetes-client-windows-386.tar.gz11c43aa66fde0efcabc23514712ea09841a780030ac325e04c8afaf176d2c1b30f77d50e44c1848005544e7a75145bd2cea1494ecbfa954ec92e9b90a139ebae
kubernetes-client-windows-amd64.tar.gzd2da1bc5d7d0b2221a74ca7cc25e89ec4031d1f85b6f8a1353caab32b64ddc2001ee75dfc6b2b0de061be3939a72e2ca6f7617a08d62c7556524664142b80163
kubernetes-client-windows-arm64.tar.gz394148251757aba7bfa8384551ea1267619489fb2e0ba522a8a90ef4be928232c4f350c14e6a7ea7636acb38a147e8ee7e4e2f625889fd133fd97d5f49d549d3

Server Binaries

filenamesha512 hash
kubernetes-server-linux-amd64.tar.gz94058098df7873521851798bd8290b8d246cd71f4071923025438f7accdb160289993ad0f5b5c9bafe4a3520eb6c7fdc6b4ad982c91bc2556f25ca3346c39db7
kubernetes-server-linux-arm64.tar.gz2707d773e6d5bd88f655ff277b7477cd78627eaf25f48b4b0b27f995b3d6d3e13314a8d2e3c149a60bdf39f2ba9d77df8e4ecf0a7c86687160da86b1a145c615
kubernetes-server-linux-ppc64le.tar.gzce98aa4d7e75fe0cb1598764de7b3ab49f81cb041128d6874452c5fd750505f7119c450ec5e5e57cf5d8cad684367ea3607c2424f9b16e3406ef3be6de161783
kubernetes-server-linux-s390x.tar.gza6a0b0c2f696ff2db16cb2ec03cc28f1e3824ad80fbc80cd8c69ae3217148a6897b089972c4ae447bdca3e2d9b44dbc981e7030729af13d2723fdf4e12065257

Node Binaries

filenamesha512 hash
kubernetes-node-linux-amd64.tar.gzc73b31d2cd8c2a332230583d039b42822d9a10a795e69e4c989039041345f4324a9120cd232c04f3c0543b2028d73078a0cc5e47b71ca905b89cd94095177391
kubernetes-node-linux-arm64.tar.gz951a083d0754b7b8c0c26e71b92c7151f42a32699ab040d9d6e86ca87f7260deb253a70bb5ed6cebfa81bf956e1c310a544327b012f19e71ccd0f35c70b212d7
kubernetes-node-linux-ppc64le.tar.gze6682ff04ffc3d047c5d9496863e8ea78b7d933d642cbc6b7531b3c995a0de0372d486f5cd4816fe0e15571dcc05bc1bcdbf8b27c43fc3b51824e64056e162b6
kubernetes-node-linux-s390x.tar.gzca81c098ba1b162103949eccf5e823b9709674e5839abed0d6e2ec386c2ef49974a18e62b46d232fcad059733854c39cc607813075c5e2eed7698d5570c0e1ef
kubernetes-node-windows-amd64.tar.gz77444c20dbfde2f96c83439aafd9385708f541dda7d3c229087f7269c32d594917d290d307426380c9456ab9d806051d85e314f50170b161253a465a9ea1d583

Container Images

All container images are available as manifest lists and support the described architectures. It is also possible to pull a specific architecture directly by adding the "-$ARCH" suffix to the container image name.

namearchitectures
registry.k8s.io/conformance:v1.32.8amd64arm64ppc64les390x
registry.k8s.io/kube-apiserver:v1.32.8amd64arm64ppc64les390x
registry.k8s.io/kube-controller-manager:v1.32.8amd64arm64ppc64les390x
registry.k8s.io/kube-proxy:v1.32.8amd64arm64ppc64les390x
registry.k8s.io/kube-scheduler:v1.32.8amd64arm64ppc64les390x
registry.k8s.io/kubectl:v1.32.8amd64arm64ppc64les390x

Changelog since v1.32.7

Important Security Information

This release contains changes that address the following vulnerabilities:

CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference

A vulnerability exists in the NodeRestriction admission controller where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection. By default, node users are authorized for create and patch requests but not delete requests against their node object. Since the NodeRestriction admission controller does not prevent patching OwnerReferences, a compromised node could leverage this vulnerability to delete and then recreate its node object with modified taints or labels.

Affected Versions:

  • kube-apiserver v1.31.0 - v1.31.11
  • kube-apiserver v1.32.0 - v1.32.7
  • kube-apiserver v1.33.0 - v1.33.3

Fixed Versions:

  • kube-apiserver v1.31.12
  • kube-apiserver v1.32.8
  • kube-apiserver v1.33.4

This vulnerability was reported by Paul Viossat.

CVSS Rating: Medium (6.7) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Changes by Kind

Feature

  • Kubernetes is now built using Go 1.23.11 (#132898@cpanato) [SIG Release and Testing]

Bug or Regression

  • Changed the node restrictions to disallow the node to change it's ownerReferences. (#133469@natherz97) [SIG Auth]

Dependencies

Added

Nothing has changed.

Changed

Nothing has changed.

Removed

Nothing has changed.



Contributors, the CHANGELOG-1.32.md has been bootstrapped with v1.32.8 release notes and you may edit now as needed.



Published by your Kubernetes Release Managers.

Reply all
Reply to author
Forward
0 new messages