CVE-2025-52889
Linux Fedora vulnerability analysis and mitigation

Overview

Incus, a system container and virtual machine manager, contains a vulnerability (CVE-2025-52889) in versions 6.12 and 6.13 where nftables rules for local services (DHCP, DNS) partially bypass security options security.macfiltering, security.ipv4filtering, and security.ipv6_filtering. The vulnerability was discovered in June 2025 and affects bridge-connected devices with ACLs (GitHub Advisory).

Technical details

The vulnerability stems from the incorrect ordering of nftables rules introduced in commit a7c3330. The rules for local services (DHCP, DNS) were placed before MAC and IP filtering rules, effectively bypassing these security controls. The issue specifically affects bridge input chain rules that accept packets that should be filtered by later MAC filtering rules. The vulnerability has been assigned a CVSS v3.1 score of 3.4 (Low) with vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L (GitHub Advisory).

Impact

The vulnerability allows attackers to bypass MAC filtering and request multiple IP addresses through DHCP requests with different MAC addresses, potentially leading to DHCP pool exhaustion and denial of service on the bridge's network. Additionally, attackers can send DNS requests with arbitrary MAC and IP addresses, as the rules allow non-restricted access to the local dnsmasq DNS server (GitHub Advisory).

Mitigation and workarounds

A patch has been released in version 6.14 that corrects the ordering of the nftables rules. The fix is available in commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214, which ensures proper filtering of packets by placing the security rules in the correct order (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Fedora vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66287HIGH8.8
  • Alma LinuxAlma Linux
  • javascriptcoregtk6.0-debuginfo
NoYesDec 04, 2025
CVE-2025-12744HIGH8.8
  • Linux FedoraLinux Fedora
  • python3-abrt-container-addon
NoYesDec 03, 2025
CVE-2025-13601HIGH7.7
  • CBL MarinerCBL Mariner
  • glib2-debuginfo
NoYesNov 26, 2025
CVE-2025-13947HIGH7.4
  • Alma LinuxAlma Linux
  • webkitgtk6.0
NoYesDec 03, 2025
CVE-2025-63938MEDIUM6.5
  • Linux DebianLinux Debian
  • tinyproxy
NoYesNov 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management