VDB
Sign up
LOW3.3

GHSA-4vq8-7jfc-9cvp

Moby firewalld reload removes bridge network isolation

Quick fix

GHSA-4vq8-7jfc-9cvp — github.com/docker/docker: upgrade to the fixed version with the command below.

go get github.com/docker/docker@v25.0.13

Details

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as [moby/moby](https://github.com/moby/moby) is commonly referred to as Docker, or Docker Engine.

Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.

### Impact

The iptables rules created by Docker are removed when firewalld is reloaded using, for example "firewall-cmd --reload", "killall -HUP firewalld", or "systemctl reload firewalld".

When that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created.

Once these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host.

Containers running in networks created with `--internal` or equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.

Where Docker Engine is not running in the host's network namespace, it is unaffected. Including, for example, Rootless Mode, and Docker Desktop.

### Patches

Moby releases 28.0.0 and newer are not affected. A fix is available in moby release 25.0.13.

### Workarounds After reloading firewalld, either: - Restart the docker daemon, - Re-create bridge networks, or - Use rootless mode.

### References https://firewalld.org/ https://firewalld.org/documentation/howto/reload-firewalld.html

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/docker/docker
Introduced in: 0Fixed in: 25.0.13
Fixgo get github.com/docker/docker@v25.0.13
Go/github.com/docker/docker
Introduced in: 26.0.0-rc1Fixed in: 28.0.0
Fixgo get github.com/docker/docker@v28.0.0

References