Security Flaw in Incus System Container and VM Manager
CVE-2025-52890

8.1HIGH

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
25 June 2025

What is CVE-2025-52890?

The Incus system container and virtual machine manager exhibits a vulnerability when using access control lists (ACLs) on devices connected to a bridge. In versions 6.12 and 6.13, it generates nftables rules that inadequately enforce security options such as security.mac_filtering, security.ipv4_filtering, and security.ipv6_filtering. This deficiency can potentially allow an attacker to execute ARP spoofing within the bridge, enabling them to impersonate another virtual machine or container sharing the same network segment. A patch addressing this issue is available in commit 254dfd2483ab8de39b47c2258b7f1cf0759231c8.

Affected Version(s)

incus >= 6.12, <= 6.13

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52890 : Security Flaw in Incus System Container and VM Manager