Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 468
Alerts This Week
Warning Icon 1 468

Fedora 42: containernetworking-plugins Faces Critical CVE-2025-47910 Issue

fedora
Calendar Grey October 5, 2025
Scroller Fedora
CVE-2025-47910 resolved in Fedora security advisory for containernetworking-plugins to mitigate critical threat.
Resolve CVE-2025-47910

Summary

Reference and example networking plugins, maintained by the CNI team.

The CNI (Container Network Interface) project consists of a specification

and libraries for writing plugins to configure network interfaces in Linux

containers, along with a number of supported plugins. CNI concerns itself

only with network connectivity of containers and removing allocated resources

when the container is deleted.

Update Information:

Resolve CVE-2025-47910

Change Log

* Fri Sep 26 2025 Bradley G Smith - 1.8.0-2 - Resolve CVE-2025-47910 - Resolves: rhbz#2398656, rhbz#2398402 - Rebuild with go 1.25.1 (fc44, fc43) or 1.24.7 (fc42, fc41)

References


[ 1 ] Bug #2398402 - CVE-2025-47910 containernetworking-plugins: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398402 [ 2 ] Bug #2398656 - CVE-2025-47910 containernetworking-plugins: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398656

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e36ffc5112' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: containernetworking-plugins
Product: Fedora 42
Version: 1.8.0
Release: 2.fc42
Summary: Reference and example networking plugins, maintained by the CNI team

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.