SB2026010826 - Improper access control in CNI Plugins
Published: January 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2025-67499)
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the portmap plugin using the nftables backend, which forwards traffic based only on the destination port. A local user can intercept all traffic destined for that port.
Remediation
Install update from vendor's website.