[Bug 1213659] New: VUL-0: CVE-2023-38496: apptainer: Ineffective privileges drop when requesting container network
https://bugzilla.suse.com/show_bug.cgi?id=1213659 Bug ID: 1213659 Summary: VUL-0: CVE-2023-38496: apptainer: Ineffective privileges drop when requesting container network Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.5 Hardware: Other URL: https://smash.suse.de/issue/373431/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: cgoll@suse.com Reporter: gianluca.gabrielli@suse.com QA Contact: qa-bugs@suse.de Target Milestone: --- Found By: --- Blocker: --- Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-38496 https://bugzilla.redhat.com/show_bug.cgi?id=2226582 https://www.cve.org/CVERecord?id=CVE-2023-38496 http://www.cvedetails.com/cve/CVE-2023-38496/ https://github.com/apptainer/apptainer/pull/1523 https://github.com/apptainer/apptainer/pull/1578 https://github.com/apptainer/apptainer/security/advisories/GHSA-mmx5-32m4-wx... -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1213659
Maintenance Automation
https://bugzilla.suse.com/show_bug.cgi?id=1213659
https://bugzilla.suse.com/show_bug.cgi?id=1213659#c1
Christian Goll
https://bugzilla.suse.com/show_bug.cgi?id=1213659
Egbert Eich
https://bugzilla.suse.com/show_bug.cgi?id=1213659
https://bugzilla.suse.com/show_bug.cgi?id=1213659#c4
Christian Goll
participants (1)
-
bugzilla_noreply@suse.com