Database/Container, Kubernetes & orchestration
Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intended
CVSS 5.1CVE-2025-54388Container, Kubernetes & orchestrationcurated
Impact
On firewalld reload, published container ports become reachable from outside despite the intended restriction
Who can reach it
Unauthenticated network
What to do
Upgrade Docker Engine; verify iptables/nftables rules after any firewalld reload
References
Related entries
- Docker / moby: IPv6 not disabled on interfaces where it should beCVE-2024-32473 · Docker / mobyMedium
- Docker / moby: Related firewalld handling defect affecting Moby port exposureCVE-2025-54410 · Docker / mobyLow
- Docker / moby: `docker cp` into a crafted container changes Unix permissions of existing host filesCVE-2021-41089 · Docker / mobyLow
- Docker / moby: Code injection into `docker cp` via nsswitch loading a library from the container chrootCVE-2019-14271 · Docker / mobyCritical
- Docker / moby: Command execution via crafted remote git build path in `docker build`CVE-2019-13139 · Docker / mobyHigh
- Docker / moby: Race condition in the streamformatter package causing data corruption or daemon crashCVE-2024-36623 · Docker / mobyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.