CVE-2025-52890Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to ARP spoofing on the bridge and to fully spoof another VM/container on the same bridge. Commit 254dfd2483ab8de39b47c2258b7f1cf0759231c8 contains a patch for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-30: 1Technical Details · 2026-03-30: 103-30
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Disclosure

    Incus users: CVE-2025-52890 is a high-severity `nftables` rule bypass in `Incus` that may affect security options. Monitor for vendor updates. #Incus #ContainerSecurity #infosec https://www.pulsepatch.io/posts/cve-2025-52890-incus-nftables-bypass

    Post summary

    The tweet warns Incus users of a high‑severity nftables rule‑bypass flaw (CVE‑2025‑52890) and urges them to watch for vendor updates.

    00000208
    5 followersView on X

Explore more