CVE-2025-54388

Published Jul 30, 2025

Last updated a year ago

Overview

Description
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including those created by Docker. While Docker should automatically recreate these rules, versions before 28.3.3 fail to recreate the specific rules that block external access to containers. This means that after a firewalld reload, containers with ports published to localhost (like 127.0.0.1:8080) become accessible from remote machines that have network routing to the Docker bridge, even though they should only be accessible from the host itself. The vulnerability only affects explicitly published ports - unpublished ports remain protected. This issue is fixed in version 28.3.3.
Source
security-advisories@github.com
NVD status
Analyzed
Products
moby

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
4.6
Impact score
2.5
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security-advisories@github.com
CWE-909

Social media

Hype score
Not currently trending
  1. Critical RCE in #SUSE SLES15 SP5 Docker images (CVE-2025-54388). Patching is step 1. Step 2 is building a resilient container security posture. Read more: 👉 https://t.co/PLDOBfE64J #Security https://t.co/OvylPb6H8T

    @Cezar_H_Linux

    23 Jan 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. - Mise à jour vers Portainer CE 2.33.0 (version LTS) pour corriger les failles CVE : CVE-2025-55198, CVE-2025-55199, CVE-2025-54388, CVE-2020-8552, CVE-2025-8556. - Mise à jour de l'icône de l'application. - https://t.co/stz2cZ0PWT https://t.co/ib6H8piNqx

    @ASUSTORIncFr

    22 Aug 2025

    59 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. URGENT: Patch #SUSE Linux Docker now! CVE-2025-54388 (Moderate) could expose container ports remotely after a firewalld reload. Read more: 👉 https://t.co/tNAGa7wgpi #Security https://t.co/CpIVLz08wP

    @Cezar_H_Linux

    21 Aug 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 SECURITY PATCH: #SUSE releases a moderate-severity update for Docker (CVE-2025-54388). Risk: Firewalld reloads can mistakenly expose container ports to remote hosts. Read more:👉 https://t.co/Xt64tJAhb9 #Security https://t.co/JlIAC9ubtU

    @Cezar_H_Linux

    21 Aug 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-54388 Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream pro… https://t.co/M7DwugEivv

    @CVEnew

    30 Jul 2025

    325 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations