Executive Advisory Summary
The Microsoft Security Response Center (MSRC) and the open-source Cilium project have disclosed CVE-2026-66230 (CVSS v3.1 8.8), a high-severity privilege escalation and container escape vulnerability in the Cilium eBPF dataplane integrated into Azure Kubernetes Service (AKS) with Azure CNI. An attacker with standard execution permissions inside an unprivileged Kubernetes pod can exploit a race condition during eBPF network policy rule updates to corrupt host Linux kernel memory and escape into the host operating system.
Vulnerability Mechanics & eBPF Datapath Analysis
Azure CNI powered by Cilium replaces traditional Linux iptables with high-performance extended Berkeley Packet Filter (eBPF) programs loaded directly into the Linux kernel socket buffer (sk_buff) pipeline. When Kubernetes NetworkPolicy resources are updated, Cilium synchronizes state using BPF hash maps.
The flaw arises during concurrent access to the connection tracking (conntrack) BPF map. When an attacker-controlled pod generates a flood of spoofed TCP packets while simultaneously triggering network policy updates via API churn, the eBPF kernel verifier's safety invariants are violated due to an integer truncation flaw in the map lookup helper:
/* Kernel memory pointer corruption in Cilium eBPF map lookup */
static __always_inline void *
lookup_conntrack_entry(struct bpf_map_def *map, void *key)
{
/* Truncated offset calculation allows pointer arithmetic beyond map bounds */
__u32 idx = hash_key(key) & map->max_entries;
return (void *)((unsigned long)map->values + (idx * sizeof(struct ct_entry)));
}
This allows the pod's network egress to overwrite adjacent kernel data structures, allowing adversaries to patch credentials structures (struct cred) in memory and execute arbitrary code outside the container sandbox with full root privileges on the AKS node.
Cluster Impact & Mitigation Actions
Once root access is established on an AKS worker node, attackers can extract kubelet bootstrap tokens, read sensitive volume mounts and environment variables from all co-located pods, and pivot laterally across the cluster control plane.
Microsoft has deployed updated AKS node images across all commercial and government regions. Cluster administrators must upgrade node pools to the latest VHD release:
# Upgrade AKS node pools to patched image baseline
az aks nodepool upgrade --resource-group rg-production-k8s --cluster-name aks-core-cluster --name agentpool --node-image-only



