CVE-2023-30549
Last modified
CVE-2023-30549 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. That includes Red Hat Enterprise Linux 7, Debian 10 buster (unless the linux-5.10 package is installed), Ubuntu 18.04 bionic and Ubuntu 20.04 focal. Use-after-free flaws in the kernel can be used to attack the kernel for denial of service and potentially for privilege escalation. Apptainer 1.1.8 includes a patch that by default disables mounting of extfs filesystem types in setuid-root mode, while continuing to allow mounting of extfs filesystems in non-setuid "rootless" mode using fuse2fs. Some workarounds are possible. Either do not install apptainer-suid (for versions 1.1.0 through 1.1.7) or set `allow setuid = no` in apptainer.conf. This requires having unprivileged user namespaces enabled and except for apptainer 1.1.x versions will disallow mounting of sif files, extfs files, and squashfs files in addition to other, less significant impacts. (Encrypted sif files are also not supported unprivileged in apptainer 1.1.x.). Alternatively, use the `limit containers` options in apptainer.conf/singularity.conf to limit sif files to trusted users, groups, and/or paths, and set `allow container extfs = no` to disallow mounting of extfs overlay files. The latter option by itself does not disallow mounting of extfs overlay partitions inside SIF files, so that's why the former options are also needed.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lfprojects | Apptainer | < 1.1.8 |
| Sylabs | Singularity | All versions |
| Redhat | Enterprise Linux | 7.0 |
References
- https://access.redhat.com/security/cve/cve-2022-1184Not Applicable
- https://github.com/apptainer/apptainer/security/advisories/GHSA-j4rf-7357-f4cgMitigation, Vendor Advisory
- https://ubuntu.com/security/CVE-2022-1184Not Applicable
- https://www.suse.com/security/cve/CVE-2022-1184.htmlNot Applicable
- https://access.redhat.com/security/cve/cve-2022-1184Not Applicable
- https://github.com/apptainer/apptainer/security/advisories/GHSA-j4rf-7357-f4cgMitigation, Vendor Advisory
- https://ubuntu.com/security/CVE-2022-1184Not Applicable
- https://www.suse.com/security/cve/CVE-2022-1184.htmlNot Applicable
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30549?
How severe is CVE-2023-30549?
How do I fix CVE-2023-30549?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30543@web3-react is a framework for building Ethereum Apps . In a…5.7
- CVE-2023-30544Kiwi TCMS is an open source test management system. In versi…4.3
- CVE-2023-30545PrestaShop is an Open Source e-commerce web application. Pri…6.5
- CVE-2023-30546Contiki-NG is an operating system for Internet of Things dev…7.5
- CVE-2023-30547vm2 is a sandbox that can run untrusted code with whiteliste…10
- CVE-2023-30548gatsby-plugin-sharp is a plugin for the gatsby framework whi…4.3
- CVE-2023-3055The Page Builder by AZEXO plugin for WordPress is vulnerable…4.3
- CVE-2023-30550MeterSphere is an open source continuous testing platform, c…4.5
- CVE-2023-30551Rekor is an open source software supply chain transparency l…7.5
- CVE-2023-30552Archery is an open source SQL audit platform. The Archery pr…6.5
- CVE-2023-30553Archery is an open source SQL audit platform. The Archery pr…6.5
- CVE-2023-30554Archery is an open source SQL audit platform. The Archery pr…6.5
Are you affected by CVE-2023-30549?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
