[Bug 1213659] New: VUL-0: CVE-2023-38496: apptainer: Ineffective privileges drop when requesting container network
https://bugzilla.suse.com/show_bug.cgi?id=1213659 Bug ID: 1213659 Summary: VUL-0: CVE-2023-38496: apptainer: Ineffective privileges drop when requesting container network Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.5 Hardware: Other URL: https://smash.suse.de/issue/373431/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: cgoll@suse.com Reporter: gianluca.gabrielli@suse.com QA Contact: qa-bugs@suse.de Target Milestone: --- Found By: --- Blocker: --- Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-38496 https://bugzilla.redhat.com/show_bug.cgi?id=2226582 https://www.cve.org/CVERecord?id=CVE-2023-38496 http://www.cvedetails.com/cve/CVE-2023-38496/ https://github.com/apptainer/apptainer/pull/1523 https://github.com/apptainer/apptainer/pull/1578 https://github.com/apptainer/apptainer/security/advisories/GHSA-mmx5-32m4-wx... -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1213659 Maintenance Automation <maint-coord+maintenance-robot@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1213659 https://bugzilla.suse.com/show_bug.cgi?id=1213659#c1 Christian Goll <cgoll@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Resolution|--- |FIXED Status|NEW |RESOLVED --- Comment #1 from Christian Goll <cgoll@suse.com> --- Although not relevant for the package as it is compiled without setuid, a fixed version is committed to factory. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1213659 Egbert Eich <eich@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Resolution|FIXED |--- Status|RESOLVED |REOPENED -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1213659 https://bugzilla.suse.com/show_bug.cgi?id=1213659#c4 Christian Goll <cgoll@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |RESOLVED Resolution|--- |FIXED --- Comment #4 from Christian Goll <cgoll@suse.com> --- Only 1.2.0 and 1.2.0-rc2 where affected. I submitted 1.2.0 to factory yesterday (26.7) and rc2 was only present in my home repo. Also the CVE wasn't relevant as we do not build the suid binary! -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1213659 Gianluca Gabrielli <gianluca.gabrielli@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Comment #0 is|1 |0 private| | -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com