GHSA-4vq8-7jfc-9cvp

    Dashboard / Vulnerabilities / GHSA-4vq8-7jfc-9cvp

    GHSA-4vq8-7jfc-9cvp

    Published: 29 Jul 2025Last Modified: 10 Sept 2026

    Summary: Moby firewalld reload removes bridge network isolation

    Details: Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as [moby/moby](https://github.com/moby/moby) is commonly referred to as Docker, or Docker Engine. Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks. ### Impact The iptables rules created by Docker are removed when firewalld is reloaded using, for example "firewall-cmd --reload", "killall -HUP firewalld", or "systemctl reload firewalld". When that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created. Once these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host. Containers running in networks created with `--internal` or equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload. Where Docker Engine is not running in the host's network namespace, it is unaffected. Including, for example, Rootless Mode, and Docker Desktop. ### Patches Moby releases 28.0.0 and newer are not affected. A fix is available in moby release 25.0.13. ### Workarounds After reloading firewalld, either: - Restart the docker daemon, - Re-create bridge networks, or - Use rootless mode. ### References https://firewalld.org/ https://firewalld.org/documentation/howto/reload-firewalld.html

    Affected packages

    Package

    Name: github.com/docker/docker

    Purl: pkg:golang/github.com/docker/docker

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -25.0.13

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High