Skip to main content

Illumio Segmentation for Kubernetes

Release Notes for Kubernetes 5.4.0

These release notes describe the new features, enhancements, resolved issues, and known issues for this release.

Resolved Issues in Release 5.4.0

Issue

Fix Description

E-127347, E-126604

Updated Universal Base Image to UBI 9.6 micro

The Universal Base Image for Kubelink and C-VEN was updated to UBI 9.6 micro to fix several golang vulnerabilities, including CVE-2025-30204, CVE-2025-30204, and CVE-2025-22869.

E-126290

Fixed RHSA-2025:1330

This vulnerability in OpenSSL was fixed in the Kubelink included in release 5.4.0.

E-124299

When running in degraded mode, Kubelink might send the wrong policy to CoreDNS pods

Policy delivery for new Kubernetes Workloads in degraded mode can be disabled by setting the Helm chart variable disableDegradedMode: true.

For more information about degraded mode, see the section on "CLAS Degraded Mode: disableDegradedMode and degradedModePolicyFail" in the "Deployment with Helm Chart" chapter on the Containers Guide.

E-123377

Fixed inaccuracies in the output of the metrics service

Two inaccuracies in the output of the metrics service have been fixed (host_policy_status running on port 8080 when in CLAS mode).