[28.x backport] Fix firewalld reload for per-endpoint rules by robmry · Pull Request #50506 · moby/moby (original) (raw)

@robmry

Make sure iptables rules are restored properly once firewalld has deleted them.

Signed-off-by: Rob Murray rob.murray@docker.com Signed-off-by: Andrey Epifanov aepifanov@mirantis.com (cherry picked from commit 6d457d9) Signed-off-by: Rob Murray rob.murray@docker.com

@aepifanov @robmry

Signed-off-by: Andrey Epifanov aepifanov@mirantis.com (cherry picked from commit 0739307) Signed-off-by: Rob Murray rob.murray@docker.com

@robmry robmry marked this pull request as ready for review

July 24, 2025 18:16

akerouanton

@robmry robmry deleted the backport-28.x/fix_firewalld_reload branch

July 25, 2025 08:14

This was referenced

Jul 31, 2025

dnegreira added a commit to dnegreira/advisories that referenced this pull request

Sep 2, 2025

@dnegreira

Update advisory for GHSA-mh63-6h87-95cp The dependency causing this CVE, golang-jwt/jwt v3.2.1, is brought in via the project's main go.mod. Due to functional changes required to move away from v3 to v4/v5, upstream maintainers are required to do the necessary changes to the project code in order to fix this vulnerability.

Update advisory for GHSA-4vq8-7jfc-9cvp This vulnerability affects Docker Engine (Moby) versions <= 25.0.12 where firewalld reload removes Docker''''s iptables rules that isolate containers in different bridge networks. Upstream maintainers must cut a release with the fix. References: 25.x backport PR: moby/moby#50445 28.x backport PR: moby/moby#50506'

Update advisory for CVE-2024-36623 This vulnerability is being detected erroneously since this issue has been fixed since docker 25.0.4 and we currently ship v25.0.8

Signed-off-by: David Negreira david.negreira@chainguard.dev

dnegreira added a commit to dnegreira/advisories that referenced this pull request

Sep 2, 2025

@dnegreira

Update advisory for GHSA-mh63-6h87-95cp The dependency causing this CVE, golang-jwt/jwt v3.2.1, is brought in via the project's main go.mod. Due to functional changes required to move away from v3 to v4/v5, upstream maintainers are required to do the necessary changes to the project code in order to fix this vulnerability.

Update advisory for GHSA-4vq8-7jfc-9cvp This vulnerability affects Docker Engine (Moby) versions <= 25.0.12 where firewalld reload removes Docker''''s iptables rules that isolate containers in different bridge networks. Upstream maintainers must cut a release with the fix. References: 25.x backport PR: moby/moby#50445 28.x backport PR: moby/moby#50506'

Update advisory for CVE-2024-36623 This vulnerability is being detected erroneously since this issue has been fixed since docker 25.0.4 and we currently ship v25.0.8

github-merge-queue Bot pushed a commit to wolfi-dev/advisories that referenced this pull request

Sep 2, 2025

@dnegreira

Update advisory for GHSA-mh63-6h87-95cp The dependency causing this CVE, golang-jwt/jwt v3.2.1, is brought in via the project's main go.mod. Due to functional changes required to move away from v3 to v4/v5, upstream maintainers are required to do the necessary changes to the project code in order to fix this vulnerability.

Update advisory for GHSA-4vq8-7jfc-9cvp This vulnerability affects Docker Engine (Moby) versions <= 25.0.12 where firewalld reload removes Docker''''s iptables rules that isolate containers in different bridge networks. Upstream maintainers must cut a release with the fix. References: 25.x backport PR: moby/moby#50445 28.x backport PR: moby/moby#50506'

Update advisory for CVE-2024-36623 This vulnerability is being detected erroneously since this issue has been fixed since docker 25.0.4 and we currently ship v25.0.8

Signed-off-by: David Negreira david.negreira@chainguard.dev

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})