FlawAtlas
Search the atlas
CVE-2023-38496 Moderate

Ineffective privileges drop when requesting container network in github.com/apptainer/apptainer

Ineffective privileges drop when requesting container network in github.com/apptainer/apptainer

Exploit probability 0.3%
Published August 20, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

3 explicit affected versions

Go github.com/apptainer/apptainer
Go github.com/apptainer/apptainer

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2023-1965

Ineffective privileges drop when requesting container network in github.com/apptainer/apptainer

View original source
Open Source Vulnerabilities GHSA-mmx5-32m4-wxvx

### Impact Fix https://github.com/apptainer/apptainer/pull/1523 included in Apptainer 1.2.0-rc.2 has introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges. The attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. Only affects setuid installations of Apptainer. ### Patches The security fix https://github.com/apptainer/apptainer/pull/1578 has been included in Apptainer 1.2.1 ### Workarounds There is no known workaround outside of upgrading to Apptainer 1.2.1

View original source
Open Source Vulnerabilities CVE-2023-38496

Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1.

View original source

05 / REFERENCES

Further evidence