PT-2026-48933 · Apptainer · Apptainer
CVE-2026-48785
·
Published
2026-06-10
·
Updated
2026-07-30
CVSS v3.1
4.8
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
apptainer versions prior to 1.5.1
Description
Incorrect path matching occurs within the
limit container paths directive. This issue specifically affects SUID installations where paths listed in limit container paths are string prefixes of other existing paths that should not be included. For example, if /scratch is listed as a permitted path but /scratch2 also exists and contains container images, the system would previously match and include /scratch2 incorrectly. The fix ensures that only images under the exactly matching path are included.Recommendations
Update apptainer to version 1.5.1.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apptainer