Unpatched extfs vulnerabilities are exploitable through suid-mode Apptainer
CVE-2023-30549
What is CVE-2023-30549?
Apptainer, an open-source container platform for Linux, has a severe use-after-free vulnerability affecting versions prior to 1.1.0 and installations that include apptainer-suid under version 1.1.8 on unpatched older operating systems. The vulnerability is particularly concerning in environments using Red Hat Enterprise Linux 7, Debian 10 buster, and Ubuntu distributions (18.04 and 20.04) where patched kernel versions are absent. Exploiting this type of flaw could lead to denial of service attacks and potential privilege escalation, posing a significant risk to system integrity. Apptainer version 1.1.8 mitigates the issue by disabling extfs filesystem type mounts in setuid-root mode by default. Users and administrators are advised to either avoid using apptainer-suid for the vulnerable versions or implement necessary configuration adjustments to enhance security.
Affected Version(s)
apptainer < 1.1.8
