/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-cwfj-w6g7-f76h

Published

Last updated

https://images.chainguard.dev/security/CGA-cwfj-w6g7-f76h
Package

gitlab-runner-18.2

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-54410
  • GHSA-4vq8-7jfc-9cvp

Severity

5.2

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54410

Updates

Status

Pending upstream fix

Impact

It is not currently possible to upgrade the version of the docker dependency due to changes in the signature of various functions. The upstream maintainers will need to make code changes in order to be able to remediate this CVE

Status

Under investigation

Status

Pending upstream fix

Impact

This vulnerability affects Docker Engine (Moby) versions <= 25.0.12 where firewalld reload removes Docker's iptables rules that isolate containers in different bridge networks. Upstream maintainers must cut a release with the fix. References: 25.x backport PR: https://github.com/moby/moby/pull/50445 28.x backport PR: https://github.com/moby/moby/pull/50506


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing