GHSA-4vq8-7jfc-9cvp
Moby firewalld reload removes bridge network isolation
Quick fix
GHSA-4vq8-7jfc-9cvp — github.com/docker/docker: upgrade to the fixed version with the command below.
go get github.com/docker/docker@v25.0.13Details
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as [moby/moby](https://github.com/moby/moby) is commonly referred to as Docker, or Docker Engine.
Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.
### Impact
The iptables rules created by Docker are removed when firewalld is reloaded using, for example "firewall-cmd --reload", "killall -HUP firewalld", or "systemctl reload firewalld".
When that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created.
Once these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host.
Containers running in networks created with `--internal` or equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.
Where Docker Engine is not running in the host's network namespace, it is unaffected. Including, for example, Rootless Mode, and Docker Desktop.
### Patches
Moby releases 28.0.0 and newer are not affected. A fix is available in moby release 25.0.13.
### Workarounds After reloading firewalld, either: - Restart the docker daemon, - Re-create bridge networks, or - Use rootless mode.
### References https://firewalld.org/ https://firewalld.org/documentation/howto/reload-firewalld.html
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 25.0.13go get github.com/docker/docker@v25.0.1326.0.0-rc1Fixed in: 28.0.0go get github.com/docker/docker@v28.0.0References
- https://github.com/moby/moby/security/advisories/GHSA-4vq8-7jfc-9cvp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-54410[ADVISORY]
- https://github.com/moby/moby/pull/49443[WEB]
- https://github.com/moby/moby/pull/49728[WEB]
- https://firewalld.org/documentation/howto/reload-firewalld.html[WEB]
- https://github.com/moby/moby[PACKAGE]