PT-2026-106237 · Apko · Apko

·

CVE-2026-105768

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions apko versions 0.2.0 through 1.4.4
Description The software allows users to build and publish OCI container images from apk packages. A flaw exists in the UserEntry.Parse and GroupEntry.Parse functions within pkg/passwd when reading UID and GID fields from /etc/passwd and /etc/group entries. The system uses strconv.Atoi to convert these fields to uint32 without performing a range check. On 64-bit platforms, negative values wrap and out-of-range values, such as 4294967296 (2^32), are truncated to 0. An attacker controlling a package installed into the image can provide an entry that appears to be an unprivileged UID or GID but is written into the final image as UID 0 or GID 0 (root). This truncated UID is also utilized when resolving the image's run-as user.
Recommendations Update to version 1.4.5.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105768

Affected Products

Apko