CVE-2025-67499: Knftables Missing Fib Daddr Local
The nftables backend configuration in a Go application (like the CNI portmap plugin) omits the 'fib daddr type local' instruction in the prerouting or output chain. This oversight allows traffic not destined for the node/host to be incorrectly intercepted and NAT-forwarded if rules match solely on port numbers. This defect can lead to unintended Man-in-the-M
greprules fetch cve-2025-67499-knftables-missing-fib-daddr-local --engine opengrepDescription
The nftables backend configuration in a Go application (like the CNI portmap plugin) omits the 'fib daddr type local' instruction in the prerouting or output chain. This oversight allows traffic not destined for the node/host to be incorrectly intercepted and NAT-forwarded if rules match solely on port numbers. This defect can lead to unintended Man-in-the-M
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.