Security Flaw in Incus System Container and VM Manager
CVE-2025-52890
8.1HIGH
What is CVE-2025-52890?
The Incus system container and virtual machine manager exhibits a vulnerability when using access control lists (ACLs) on devices connected to a bridge. In versions 6.12 and 6.13, it generates nftables rules that inadequately enforce security options such as security.mac_filtering
, security.ipv4_filtering
, and security.ipv6_filtering
. This deficiency can potentially allow an attacker to execute ARP spoofing within the bridge, enabling them to impersonate another virtual machine or container sharing the same network segment. A patch addressing this issue is available in commit 254dfd2483ab8de39b47c2258b7f1cf0759231c8.
Affected Version(s)
incus >= 6.12, <= 6.13