/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-cwfj-w6g7-f76h

Published

Last updated

https://images.chainguard.dev/security/CGA-cwfj-w6g7-f76h
Package

gitlab-runner-18.2

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-54410
  • GHSA-4vq8-7jfc-9cvp

Severity

3.3

Low

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54410

Updates

Status

Pending upstream fix

Impact

It is not currently possible to upgrade the version of the docker dependency due to changes in the signature of various functions. The upstream maintainers will need to make code changes in order to be able to remediate this CVE

Status

Under investigation

Status

Pending upstream fix

Impact

This vulnerability affects Docker Engine (Moby) versions <= 25.0.12 where firewalld reload removes Docker's iptables rules that isolate containers in different bridge networks. Upstream maintainers must cut a release with the fix. References: 25.x backport PR: https://github.com/moby/moby/pull/50445 28.x backport PR: https://github.com/moby/moby/pull/50506


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing