Your message dated Mon, 14 Sep 2026 11:25:11 -0400
with message-id <[email protected]>
and subject line Closing #1110408: CVE-2025-54410 (fixed in 28.5.2+dfsg1-1)
has caused the Debian Bug report #1110408,
regarding docker.io: CVE-2025-54410
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1110408: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1110408
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: docker.io
Version: 26.1.5+dfsg1-9
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for docker.io.

CVE-2025-54410[0]:
| Moby is an open source container framework developed by Docker Inc.
| that is distributed as Docker Engine, Mirantis Container Runtime,
| and various other downstream projects/products. A firewalld
| vulnerability affects Moby releases before 28.0.0. When firewalld
| reloads, Docker fails to re-create iptables rules that isolate
| bridge networks, allowing any container to access all ports on any
| other container across different bridge networks on the same host.
| This breaks network segmentation between containers that should be
| isolated, creating significant risk in multi-tenant environments.
| Only containers in --internal networks remain protected. Workarounds
| include reloading firewalld and either restarting the docker daemon,
| re-creating bridge networks, or using rootless mode. Maintainers
| anticipate a fix for this issue in version 25.0.13.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-54410
    https://www.cve.org/CVERecord?id=CVE-2025-54410
[1] https://github.com/moby/moby/security/advisories/GHSA-4vq8-7jfc-9cvp

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Version: 28.5.2+dfsg1-1

Hi Salvatore,

As noted in the upstream advisory (GHSA-4vq8-7jfc-9cvp), CVE-2025-54410
affects Moby releases prior to 28.0.0 and was fixed upstream in Moby 28.0.0.

In Debian unstable (sid), docker.io was upgraded to the 28.x series in
version 28.5.2+dfsg1-1, where this vulnerability is resolved.

I am therefore closing this bug with version 28.5.2+dfsg1-1.

Thanks,
Reinhard

--- End Message ---

Reply via email to