Missing initialization of resource in moby - CVE-2025-54410
Published: October 15, 2025
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to Docker fails to re-create iptables rules that isolate bridge networks when firewalld reloads, allowing any container to access all ports on any other container across different bridge networks on the same host. This breaks network segmentation between containers that should be isolated, creating significant risk in multi-tenant environments. A local user can gain unauthorized access to sensitive information on the system.
Affected software
Astronomer with IBM
Guardium Data Security Center (GDSC)
Maximo Application Suite - IoT Component
BIG-IP Next CNF
BIG-IP Next SPK
BIG-IP Next for Kubernetes
Netcool Operations Insight
IBM Maximo Application Suite
watsonx.data
IBM Edge Application Manager
How to mitigate CVE-2025-54410
Astronomer with IBM - update to 1.1.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.2
Guardium Data Security Center (GDSC) - update to 3.8.5
Maximo Application Suite - IoT Component - addressed in versions 8.7.29, 8.8.26, 9.0.15, 9.1.6
IBM Maximo Application Suite - addressed in versions 8.10.32, 8.11.29, 9.0.18, 9.1.7
External References
Related Security Bulletins
- Missing initialization of resource in Moby
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Maximo Application Suite
- IBM watsonx.data update for Moby
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Astronomer with IBM update for Moby
- Information disclosure in BIG-IP Next Moby