{"schema_version":"1.9.0","id":"GHSA-x4rx-4gw3-53p4","published":"2025-07-29T19:56:22Z","modified":"2026-09-10T03:50:26.417777166Z","aliases":["CVE-2025-54388","GO-2025-3830"],"summary":"Moby firewalld reload makes published container ports accessible from remote hosts ","details":"Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as [moby/moby](https://github.com/moby/moby) is commonly referred to as Docker, or Docker Engine.\n\nFirewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.\n\n### Impact\n\nThe iptables rules created by Docker are removed when firewalld is reloaded using, for example \"firewall-cmd --reload\", \"killall -HUP firewalld\", or \"systemctl reload firewalld\".\n\nWhen that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that prevent packets arriving on a host interface from reaching container addresses are not re-created.\n\nOnce these rules have been removed, a remote host configured with a route to a Docker bridge network can access published ports, even when those ports were only published to a loopback address. Unpublished ports remain inaccessible.\n\nFor example, following a firewalld reload on a Docker host with address `192.168.0.10` and a bridge network with subnet `172.17.0.0/16`, running the following command on another host in the local network will give it access to published ports on container addresses in that network: `ip route add 172.17.0.0/16 via 192.168.0.10`.\n\nContainers running in networks created with `--internal` or equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.\n\nWhere Docker Engine is not running in the host's network namespace, it is unaffected. Including, for example, Rootless Mode, and Docker Desktop.\n\n### Patches\n\nMoby releases older than 28.2.0 are not affected. A fix is available in moby release 28.3.3.\n\n### Workarounds\nAfter reloading firewalld, either:\n- Restart the docker daemon,\n- Re-create bridge networks, or\n- Use rootless mode.\n\n### References\nhttps://firewalld.org/\nhttps://firewalld.org/documentation/howto/reload-firewalld.html","affected":[{"package":{"name":"github.com/docker/docker","ecosystem":"Go","purl":"pkg:golang/github.com/docker/docker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"28.2.0"},{"fixed":"28.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-x4rx-4gw3-53p4/GHSA-x4rx-4gw3-53p4.json"}}],"references":[{"type":"WEB","url":"https://github.com/moby/moby/security/advisories/GHSA-x4rx-4gw3-53p4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54388"},{"type":"WEB","url":"https://github.com/moby/moby/pull/50506"},{"type":"WEB","url":"https://github.com/moby/moby/commit/bea959c7b793b32a893820b97c4eadc7c87fabb0"},{"type":"PACKAGE","url":"https://github.com/moby/moby"}],"database_specific":{"cwe_ids":["CWE-909"],"github_reviewed":true,"github_reviewed_at":"2025-07-29T19:56:22Z","nvd_published_at":"2025-07-30T14:15:28Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"}]}