<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:49:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-08084</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08084</link>
      <description>bdu:2025-08084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08084</guid>
    </item>
    <item>
      <title>EUVD-2026-245856</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-245856</link>
      <description>EUVD-2026-245856</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-245856</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52889</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52889</link>
      <description>&lt;p&gt;Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks. A patch is available at commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks. A patch is available at commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52889</guid>
    </item>
    <item>
      <title>GHSA-9q7c-qmhm-jv86 — Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9q7c-qmhm-jv86</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When using an ACL on a device connected to a bridge, Incus generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In commit a7c33301738aede3c035063e973b1d885d9bac7c, the following rules are added at the top of the bridge input chain:&lt;/p&gt;
&lt;p&gt;iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip ip saddr 0.0.0.0 ip daddr 255.255.255.255 udp dport 67 accept
	iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip6 ip6 saddr fe80::/10 ip6 daddr ff02::1:2 udp dport 547 accept
	iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip6 ip6 saddr fe80::/10 ip6 daddr ff02::2 icmpv6 type 133 accept&lt;/p&gt;
&lt;p&gt;However, these rules accept packets that should be filtered and maybe dropped by later rules in the &amp;#34;MAC filtering&amp;#34; snippet:&lt;/p&gt;
&lt;p&gt;iifname &amp;#34;{{.hostName}}&amp;#34; ether type arp arp saddr ether != {{.hwAddr}} drop
	iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip6 icmpv6 type 136 @nh,528,48 != {{.hwAddrHex}} drop&lt;/p&gt;
&lt;p&gt;Therefore, the MAC filtering is ineffective on those new rules. This allows an attacker to request as many IP as they want by sending a lot of DHCP requests with different MAC addresses. Doing so, they can exhaust the DHCP pool, resulting in a DoS of the bridge&amp;#39;s network.&lt;/p&gt;
&lt;p&gt;Additionaly, the commit adds non-restricted access to the local dnsmasq DNS server:&lt;/p&gt;
&lt;p&gt;{{ if .dnsIPv4 }}
	{{ range .dnsIPv4 }}
	iifname &amp;#34;{{$.hostName}}&amp;#34; ip daddr &amp;#34;{{…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When using an ACL on a device connected to a bridge, Incus generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In commit a7c33301738aede3c035063e973b1d885d9bac7c, the following rules are added at the top of the bridge input chain:&lt;/p&gt;
&lt;p&gt;iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip ip saddr 0.0.0.0 ip daddr 255.255.255.255 udp dport 67 accept
	iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip6 ip6 saddr fe80::/10 ip6 daddr ff02::1:2 udp dport 547 accept
	iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip6 ip6 saddr fe80::/10 ip6 daddr ff02::2 icmpv6 type 133 accept&lt;/p&gt;
&lt;p&gt;However, these rules accept packets that should be filtered and maybe dropped by later rules in the &amp;#34;MAC filtering&amp;#34; snippet:&lt;/p&gt;
&lt;p&gt;iifname &amp;#34;{{.hostName}}&amp;#34; ether type arp arp saddr ether != {{.hwAddr}} drop
	iifname &amp;#34;{{.hostName}}&amp;#34; ether type ip6 icmpv6 type 136 @nh,528,48 != {{.hwAddrHex}} drop&lt;/p&gt;
&lt;p&gt;Therefore, the MAC filtering is ineffective on those new rules. This allows an attacker to request as many IP as they want by sending a lot of DHCP requests with different MAC addresses. Doing so, they can exhaust the DHCP pool, resulting in a DoS of the bridge&amp;#39;s network.&lt;/p&gt;
&lt;p&gt;Additionaly, the commit adds non-restricted access to the local dnsmasq DNS server:&lt;/p&gt;
&lt;p&gt;{{ if .dnsIPv4 }}
	{{ range .dnsIPv4 }}
	iifname &amp;#34;{{$.hostName}}&amp;#34; ip daddr &amp;#34;{{…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9q7c-qmhm-jv86</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15317-1 — incus-6.14-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15317-1</link>
      <description>&lt;p&gt;incus-6.14-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;incus-6.14-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15317-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-52889</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52889</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks. A patch is available at commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks. A patch is available at commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52889</guid>
    </item>
  </channel>
</rss>
