PT-2026-106237 · Apko · Apko
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
apko versions 0.2.0 through 1.4.4
Description
The software allows users to build and publish OCI container images from apk packages. A flaw exists in the
UserEntry.Parse and GroupEntry.Parse functions within pkg/passwd when reading UID and GID fields from /etc/passwd and /etc/group entries. The system uses strconv.Atoi to convert these fields to uint32 without performing a range check. On 64-bit platforms, negative values wrap and out-of-range values, such as 4294967296 (2^32), are truncated to 0. An attacker controlling a package installed into the image can provide an entry that appears to be an unprivileged UID or GID but is written into the final image as UID 0 or GID 0 (root). This truncated UID is also utilized when resolving the image's run-as user.Recommendations
Update to version 1.4.5.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apko