Unpatched extfs vulnerabilities are exploitable through suid-mode Apptainer
CVE-2023-30549

7.1HIGH

Key Information:

Vendor

Apptainer

Status
Vendor
CVE Published:
25 April 2023

What is CVE-2023-30549?

Apptainer, an open-source container platform for Linux, has a severe use-after-free vulnerability affecting versions prior to 1.1.0 and installations that include apptainer-suid under version 1.1.8 on unpatched older operating systems. The vulnerability is particularly concerning in environments using Red Hat Enterprise Linux 7, Debian 10 buster, and Ubuntu distributions (18.04 and 20.04) where patched kernel versions are absent. Exploiting this type of flaw could lead to denial of service attacks and potential privilege escalation, posing a significant risk to system integrity. Apptainer version 1.1.8 mitigates the issue by disabling extfs filesystem type mounts in setuid-root mode by default. Users and administrators are advised to either avoid using apptainer-suid for the vulnerable versions or implement necessary configuration adjustments to enhance security.

Affected Version(s)

apptainer < 1.1.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.