PT-2025-31369 · Docker +3 · Docker Engine +5

Vvoland

·

Published

2025-07-29

·

Updated

2025-07-31

·

CVE-2025-54410

CVSS v3.1
3.3
VectorAV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

Moby versions prior to 28.0.0

Moby version 25.0.13

Description:

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby, where reloading firewalld causes Docker to fail to re-create iptables rules that isolate bridge networks. This allows containers to access any port on any other container across different bridge networks on the same host, breaking network segmentation between containers. Containers in `--internal` networks remain protected.

Recommendations:

Update to Moby version 28.0.0 or later.

Apply the fix available in Moby release 25.0.13.

As a temporary workaround, restart the docker daemon after reloading firewalld.

As a temporary workaround, re-create bridge networks after reloading firewalld.

As a temporary workaround, use rootless mode.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54410
GHSA-4VQ8-7JFC-9CVP

Affected Products

Debian
Docker
Docker Engine
Mirantis Container Runtime
Moby
Red Os