{"id":"CVE-2025-54410","aliases":["GHSA-4vq8-7jfc-9cvp","GO-2025-3829"],"url":"https://o3.security/vulnerability/CVE-2025-54410","summary":"Moby's Firewalld reload removes bridge network isolation","details":"Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as [moby/moby](https://github.com/moby/moby) is commonly referred to as Docker, or Docker Engine.\n\nFirewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.\n\n### Impact\n\nThe iptables rules created by Docker are removed when firewalld is reloaded using, for example \"firewall-cmd --reload\", \"killall -HUP firewalld\", or \"systemctl reload firewalld\".\n\nWhen that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created.\n\nOnce these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host.\n\nContainers running in networks created with `--internal` or equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.\n\nWhere Docker Engine is not running in the host's network namespace, it is unaffected. Including, for example, Rootless Mode, and Docker Desktop.\n\n### Patches\n\nMoby releases 28.0.0 and newer are not affected. A fix is available in moby release 25.0.13.\n\n### Workarounds\nAfter reloading firewalld, either:\n- Restart the docker daemon,\n- Re-create bridge networks, or\n- Use rootless mode.\n\n### References\nhttps://firewalld.org/\nhttps://firewalld.org/documentation/howto/reload-firewalld.html","published":"2025-07-30T13:24:50.818Z","modified":"2026-08-12T03:51:32.136054209Z","cvss":{"score":3.3,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.00155,"percentile":0.05043,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/docker/docker","fixedVersion":"25.0.13"},{"ecosystem":"Go","name":"github.com/docker/docker","fixedVersion":"28.0.0"}],"fix":{"url":"https://github.com/moby/moby/pull/49443","label":"moby/moby#49443"},"references":[{"type":"WEB","url":"https://firewalld.org/documentation/howto/reload-firewalld.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54410.json"},{"type":"ADVISORY","url":"https://github.com/moby/moby/security/advisories/GHSA-4vq8-7jfc-9cvp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54410"},{"type":"WEB","url":"https://github.com/moby/moby/pull/49443"},{"type":"WEB","url":"https://github.com/moby/moby/pull/49728"},{"type":"PACKAGE","url":"https://github.com/moby/moby"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.136054209Z"}}