Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-65105

Опубликовано: 02 дек. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor: and --security=selinux: which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as being a feature for the root user, although these forms do also work for unprivileged users on systems where the corresponding feature is enabled. Apparmor is enabled by default on Debian-based distributions and SElinux is enabled by default on RHEL-based distributions, but on SUSE it depends on the distribution version. This vulnerability is fixed in 1.4.5.

A flaw was found in Apptainer. This vulnerability allows a container to disable the --security=apparmor: and --security=selinux: options, bypassing security restrictions on container operations via the --security option. This affects unprivileged users on systems where Apparmor or SELinux (Security-Enhanced Linux) are enabled.

Отчет

This vulnerability is rated Moderate for Red Hat because Apptainer, when running containers on RHEL-based systems with SELinux enabled, allows a container to bypass the intended security restrictions provided by the --security=selinux option. This could lead to a reduction in the security posture of the container, even when the option is explicitly used.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2418392Apptainer: Apptainer: Security bypass due to disabling security options

EPSS

Процентиль: 6%
0.00024
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
ubuntu
4 месяца назад

Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor:<profile> and --security=selinux:<label> which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as being a feature for the root user, although these forms do also work for unprivileged users on systems where the corresponding feature is enabled. Apparmor is enabled by default on Debian-based distributions and SElinux is enabled by default on RHEL-based distributions, but on SUSE it depends on the distribution version. This vulnerability is fixed in 1.4.5.

CVSS3: 4.5
nvd
4 месяца назад

Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor:<profile> and --security=selinux:<label> which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as being a feature for the root user, although these forms do also work for unprivileged users on systems where the corresponding feature is enabled. Apparmor is enabled by default on Debian-based distributions and SElinux is enabled by default on RHEL-based distributions, but on SUSE it depends on the distribution version. This vulnerability is fixed in 1.4.5.

CVSS3: 4.5
debian
4 месяца назад

Apptainer is an open source container platform. In Apptainer versions ...

CVSS3: 4.5
github
4 месяца назад

Apptainer ineffectively applies selinux and apparmor --security options

suse-cvrf
около 2 месяцев назад

Security update for apptainer

EPSS

Процентиль: 6%
0.00024
Низкий

5.3 Medium

CVSS3