{"id":"openSUSE-SU-2026:20942-1","summary":"Security update for apptainer","details":"This update for apptainer fixes the following issues:\n\nChanges in apptainer:\n\n- Update apptainer to version v1.5.1\n  * Security fix (bsc#1267982):\n    Fix for CVE-2026-48785 / GHSA-cr2j-534f-mf3g. Incorrect path\n    matching for limit container paths directive. This is only\n    applicable to SUID installations that have paths listed in\n    limit container paths that are string prefixes of other paths\n    which are not desired to be included in the list. For example,\n    if /scratch is in the list but `/scratch2` also exists and contains\n    container images, previously the latter would match but now\n    only images under the exactly matching `/scratch` are included.\n  Other changes:\n  * Work around segmentation fault sometimes seen while `mksquashfs`\n    under proot is creating a SIF file.\n  * Update bundled PRoot to version 5.4.0-rootless.3 in order to\n    fix a problem where SIF files could be corrupted when\n    `mksquashfs` died with a signal. The proot command was not\n    passing back an error exit code.\n  * Updated bundled `squashfuse_ll` to version 0.6.2 in order to\n    fix a crash sometimes seen with apptainer in unprivileged\n    docker.\n  * Update bundled fuse2fs to version 1.47.4 instead of patching\n    the bugs in 1.47.3.\n  * Fix a crash that happened when `/etc/resolv.conf` was a\n    symlink while building from a definition file using the\n    localimage bootstrap.\n  * Support hosts that have an /etc/resolv.conf symlink pointing\n    to `../run` in addition to `/run`.\n  * Change the download-dependencies script to skip downloading\n    the PRoot source code on architectures that it is known to\n    not support (that is: ppc*, s390*, and riscv*).\n    In those situations Apptainer will skip trying to compile\n    and run proot. As a result original owners and groups of\n    files will not be preserved in SIF images built by\n    unprivileged users, as was the case for all architectures\n    prior to 1.5.0.\n  * Fix panic encountered during progress bar update while\n    pulling image.\n  * Fix fakeroot overwriting root's username in `/etc/passwd`\n    with the host user's name, a regression introduced in v1.5.0.\n  * Add nonested flag for --mount specifications to prevent\n    individual bind mounts from being passed to nested containers\n    via `APPTAINER_BIND`.\n    Example: `--mount type=bind,source=/data,destination=/mnt,nonested`.\n- Changes from version v1.5.0:\n   New Features & Functionalities\n   * Add support for a subset of the Container Device Interface\n     (CDI) standard through new `--device` and\n     `--cdi-dirs run/shell/exec` options. Honors environment\n     variable settings, bind mounts, and device files listed in\n     CDI specification files.\n   * Add support for selective mounting of Intel(R) Gaudi\n     accelerators. This feature is only for use in combination\n     with a minimal /dev directory, selected either with the\n     `--contain` flag or by configuring mount dev with the minimal\n     option; otherwise all the devices are available anyway. This\n     feature is enabled via the `--intel-hpu option` and by\n     specifying the HABANA_VISIBLE_DEVICES environment variable,\n     which should contain a comma-separated list of device IDs\n     (e.g., \"1,2,3\") or \"all\" to import all of them.\n     The default if `HABANA_VISIBLE_DEVICES` is not set is \"all\".\n   * Add support for downloading SIF images from an IPFS\n     peer-to-peer cluster using an HTTP gateway (similar to the\n     existing support for IPFS in the curl tool). The address of\n     the gateway can be set in the `IPFS_GATEWAY` environment\n     variable or read from ~/.ipfs/gateway or /etc/ipfs/gateway.\n   * Add `--no-env` action and instance option and corresponding\n     `APPTAINER_NOENV` environment variable that can provide a\n     comma-separated list of environment variables to skip\n     importing from the host environment into the container.\n   * Add `--data` build option which creates a SIF file with\n     a squashfs data partition instead of a code partition,\n     given an existing squashfs file as the source.\n   * If `PREPEND_LD_LIBRARY_PATH` is set in the container\n     environment (through an `--env` option, an `APPTAINERENV_`\n     prefix from the host, or in the container definition)\n     then prepend that string to `:$LD_LIBRARY_PATH`. Likewise\n     if `APPEND_LD_LIBRARY_PATH` is set in the container\n     environment then append that string to `$LD_LIBRARY_PATH:`.\n     This is only done when `LD_LIBRARY_PATH` is set, although\n     if the container is based on glibc, when `LD_LIBRARY_PATH`\n     is not set it will first be filled with the default\n     library search path as found through ldconfig.\n   * Create reproducible SIF images, if the environment variable\n     `SOURCE_DATE_EPOCH` has been set (as a Unix timestamp given\n     as seconds since the beginning of 1970, in the UTC timezone).\n     Also add `--reproducible` flag to build and pull from\n     `oras://` sources. This sets `SOURCE_DATE_EPOCH`\n     automatically from the image \"created\" time.\n   * Support hosts that have `/etc/resolv.conf` pointing to a\n     symlink under /run, such as those hosts that are running\n     systemd-resolved. In this case, the symlink is copied into\n     the container and the parent directory of the target of the\n     symlink is bind-mounted from the host. The result is that\n     even if the target of the symlink is replaced with a new file,\n     the container sees the update in `/etc/resolv.conf`.\n   * Add `/etc/resolv.conf` to the list of host paths that can be\n     prevented from automatic import into the container with the\n     `--no-mount` option.\n   * Preserve owner and group information on files in containers\n     downloaded from OCI registries when building SIF files, even\n     for unprivileged users. This takes advantage of the fact that\n     the library (umoci) that downloads containers preserves owner\n     and group information in an extended attribute. Adds bundled\n     tool proot which is modified from the upstream tool by the\n     rootless-containers project to make the owner and group appear\n     to be in the ordinary `stat()` information. That tool is now\n     used when invoking mksquashfs to create the filesystem\n     partition in a SIF file. It can be disabled with the hidden\n     build option `--ignore-proot`.\n   * When unsquashing an image while running under a root-mapped\n     user namespace (such as when using fakeroot without subuid\n     mapping), insert another namespace mapping back to the\n     original user so unsquashfs doesn't try (and fail) to change\n     the owner and group information on the unpacked files.\n   * Record image digest metadata (sha256 from RepoDigests), for\n     OCI registry images. Also add the image name (ref) of the\n     image from \"docker\", with registry and tag. This is useful\n     for traceability, when using docker.io or a tag like latest.\n     Unfortunately the feature does not work with \"docker-archive\"\n     or \"docker-daemon\".\n   * Apptainer now supports the `loong64` architecture.\n   Changed defaults / behaviours\n   * If libraries are bound in to `/.singularity.d/libs` (such as\n     with GPU options like `--nv`) and the container is based on\n     glibc and `LD_LIBRARY_PATH` is not already set, it is now set\n     to the default library search path. Since `/.singularity.d/libs`\n    is appended to `LD_LIBRARY_PATH`, this makes libraries\n    installed in the container take precedence over libraries\n    bound in from the host. This reduces the chances of mismatched\n    glibc versions. However, if there are indeed libraries on the\n    host that need to take precedence over libraries in the\n    container, that can be forced with\n    `PREPEND_LD_LIBRARY_PATH=/.singularity.d/libs`.\n  * Change the default arm variant to v7, and stop using the GOARM\n    environment variable. The variables GOOS, GOARCH and GOARM\n    are only used when building.\n  * The oras transport now supports architectures beyond amd64.\n    Images downloaded from oras without using the cache are now\n    checksummed. A progress bar is shown during the process.\n    Add support for APPTAINER_TMPDIR to the commands apptainer\n    overlay create and apptainer plugin compile.\n  Bug Fixes:\n   * Make the root default capabilities configuration option apply\n     only to the real root user as documented and not to a\n     fakeroot user.\n   * Fix long-time bug in importing environment variables from oci\n     containers (defined by `ENV` in their definition file) with\n     shell characters in them. It now escapes them with single\n     backslashes instead of double backslashes so they behave\n     like they do in podman and docker.\n   * The username in `/etc/passwd` inside a container now always\n     corresponds to the username of the user on the host even if\n     an entry with the same UID is found in the container.\n   * When apptainer reinvokes itself on behalf of the run-help\n     command, it passes through `LD_LIBRARY_PATH`. This makes it\n     work correctly when it was installed with\n     `install-unprivileged.sh` on a host operating system that's\n     different than the one the installed binaries were built on.\n","modified":"2026-06-13T18:24:16.948682290Z","published":"2026-06-10T14:46:21Z","related":["CVE-2026-48785"],"upstream":["CVE-2026-48785"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48785"}],"affected":[{"package":{"name":"apptainer","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/apptainer&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.1-bp160.1.1","apptainer-leap":"1.5.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20942-1.json"}}],"schema_version":"1.7.5"}