The Microsoft Security Response Center (MSRC) has addressed a maximum-criticality container escape vulnerability (CVE-2026-47182, CVSS 9.8) within Azure Kubernetes Service (AKS) clusters utilizing the Azure CNI Powered by Cilium eBPF network dataplane. The flaw enables threat actors with initial code execution inside an unprivileged container pod to bypass Linux kernel boundary protections and seize complete root control over the underlying Azure virtual machine node.
Vulnerability Dissection: eBPF Verifier Range Tracking Flaw (CWE-787)
Extended Berkeley Packet Filter (eBPF) allows the Linux kernel to run sandboxed bytecode inside the kernel space without changing kernel source code or loading kernel modules. In modern Kubernetes networking, Cilium compiles dynamic eBPF programs to accelerate packet filtering, service routing, and network policy enforcement.
According to MSRC's security bulletin, a flaw existed in the kernel verifier's mathematical 32-bit to 64-bit bounds tracking logic during signed bitwise shift operations (BPF_RSH). An attacker crafts an eBPF program where the verifier believes a register contains a guaranteed positive scalar value between 0 and 64, while runtime execution actually produces a negative offset:
// Weaponized eBPF bytecode snippet triggering verifier desynchronization
BPF_MOV64_IMM(BPF_REG_2, 0),
BPF_JMP_IMM(BPF_JEQ, BPF_REG_2, 0, 1), // Force verifier speculative branch
BPF_MOV64_IMM(BPF_REG_2, -1),
BPF_ALU64_IMM(BPF_RSH, BPF_REG_2, 32), // Verifier miscalculates bounds as [0, 0]
// Out-of-bounds pointer arithmetic on kernel map element
BPF_ALU64_REG(BPF_ADD, BPF_REG_1, BPF_REG_2), // BPF_REG_1 now points outside map slab
By writing past the boundaries of the eBPF map memory slab, the malicious program can overwrite kernel credential structures (struct cred) and kernel function pointers, elevating the container process directly to host root (UID 0).
Container Escape and Cloud Tenant Exposure
Once an adversary breaks out of container namespaces into the host node operating system:
- Kubelet Token Harvesting: The attacker extracts node bootstrap tokens and service account secrets from
/var/lib/kubelet/, enabling horizontal API privilege escalation. - Cross-Pod Interception: The adversary accesses co-hosted tenant workloads, database connection strings, and internal microservice traffic flowing across the virtual bridge.
- IMDS Instance Role Theft: The host node can query the Azure Instance Metadata Service (IMDS) to steal Managed Identity OAuth tokens assigned to the node pool.
Remediation and Node Pool Upgrade Guide
Microsoft deployed patched VHD images across all global Azure regions. AKS administrators should execute node image upgrades immediately:
# Upgrade AKS node pools to the latest patched Azure Linux / Ubuntu node image
az aks nodepool upgrade \
--resource-group ProductionRG \
--cluster-name EnterpriseAKSCluster \
--name systempool \
--node-image-only
| Platform | Vulnerable Component | Remediation Requirement |
|---|---|---|
| Managed AKS | Azure CNI Powered by Cilium | Run az aks upgrade --node-image-only on all node pools. |
| Self-Hosted Cilium | Cilium < 1.16.2 | Upgrade Cilium Helm charts to v1.16.2 or later. |
| Kernel Settings | kernel.unprivileged_bpf_disabled |
Verify sysctl kernel.unprivileged_bpf_disabled=2 is enforced across all worker nodes. |



