{"id":"UBUNTU-CVE-2025-65105","details":"Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor:\u003cprofile\u003e and --security=selinux:\u003clabel\u003e which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as being a feature for the root user, although these forms do also work for unprivileged users on systems where the corresponding feature is enabled. Apparmor is enabled by default on Debian-based distributions and SElinux is enabled by default on RHEL-based distributions, but on SUSE it depends on the distribution version. This vulnerability is fixed in 1.4.5.","modified":"2026-05-20T16:11:27.837200951Z","published":"2025-12-02T18:15:00Z","upstream":["CVE-2025-65105"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-65105"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-65105"},{"type":"REPORT","url":"https://github.com/apptainer/apptainer/security/advisories/GHSA-j3rw-fx6g-q46j"},{"type":"REPORT","url":"https://github.com/apptainer/apptainer/commit/4313b42717e18a4add7dd7503528bc15af905981"},{"type":"REPORT","url":"https://github.com/apptainer/apptainer/commit/82f17900a0c31bc769bf9b4612d271c7068d8bf2"},{"type":"REPORT","url":"https://github.com/apptainer/apptainer/pull/3226"},{"type":"REPORT","url":"https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm"},{"type":"REPORT","url":"https://github.com/sylabs/singularity/security/advisories/GHSA-wwrx-w7c9-rf87"}],"affected":[{"package":{"name":"apptainer","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/apptainer?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.0-5","1.4.0-6"],"ecosystem_specific":{"binaries":[{"binary_version":"1.4.0-6","binary_name":"apptainer"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-65105.json"}},{"package":{"name":"apptainer","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/apptainer?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.0-6","1.4.4-1","1.4.4-2","1.4.5-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.4.5-1","binary_name":"apptainer"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-65105.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}