CVE-2025-67499

Description

A flaw was found in the CNI (Container Network Interface) portmap plugin. This vulnerability allows containers to intercept all traffic destined for a host port via inadvertent forwarding of traffic with the same destination port when the plugin is configured with the nftables backend, ignoring the destination IP.

Statement

This vulnerability is rated Moderate for Red Hat because it allows containers to intercept non-local traffic when the CNI portmap plugin is explicitly configured to use the nftables backend. This issue affects CNI portmap plugin versions 1.6.0 through 1.8.0. Red Hat products are only affected if the nftables backend is specifically enabled for the CNI portmap plugin.

Mitigation

Configure the CNI portmap plugin to use the `iptables` backend instead of `nftables`. This can typically be achieved by modifying the CNI network configuration. After making this configuration change, services utilizing the CNI portmap plugin may require a restart or reload for the changes to take effect.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.63.6N/A
Attack VectorLocalLocalN/A
Attack ComplexityLowHighN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityLowLowN/A
Integrity ImpactLowLowN/A
Availability ImpactHighNoneN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

NVD: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.