Security Flaw in Incus System Container and VM Manager
CVE-2025-52890
What is CVE-2025-52890?
The Incus system container and virtual machine manager exhibits a vulnerability when using access control lists (ACLs) on devices connected to a bridge. In versions 6.12 and 6.13, it generates nftables rules that inadequately enforce security options such as security.mac_filtering, security.ipv4_filtering, and security.ipv6_filtering. This deficiency can potentially allow an attacker to execute ARP spoofing within the bridge, enabling them to impersonate another virtual machine or container sharing the same network segment. A patch addressing this issue is available in commit 254dfd2483ab8de39b47c2258b7f1cf0759231c8.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
incus >= 6.12, <= 6.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
