Security Bypass in Incus System Container and VM Manager
CVE-2025-52889
3.4LOW
What is CVE-2025-52889?
The Incus system container and virtual machine manager has a vulnerability where ACLs on devices connected to bridges generate nftables rules for local services. This affects versions 6.12 and 6.13, allowing certain security options, such as security.mac_filtering
, security.ipv4_filtering
, and security.ipv6_filtering
, to be partially bypassed. As a result, attackers could exploit this flaw to exhaust DHCP pools and potentially carry out additional attacks. A patch has been provided in commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.
Affected Version(s)
incus >= 6.12, <= 6.13