Security Bypass in Incus System Container and VM Manager
CVE-2025-52889

3.4LOW

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
25 June 2025

What is CVE-2025-52889?

The Incus system container and virtual machine manager has a vulnerability where ACLs on devices connected to bridges generate nftables rules for local services. This affects versions 6.12 and 6.13, allowing certain security options, such as security.mac_filtering, security.ipv4_filtering, and security.ipv6_filtering, to be partially bypassed. As a result, attackers could exploit this flaw to exhaust DHCP pools and potentially carry out additional attacks. A patch has been provided in commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.

Affected Version(s)

incus >= 6.12, <= 6.13

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52889 : Security Bypass in Incus System Container and VM Manager