已开启
CVE-2025-65105 #8
openeuler-ci-bot创建于  2025年12月3日
openeuler-ci-bot
openeuler-ci-bot成员
2025年12月3日 创建

一、漏洞信息
漏洞编号:CVE-2025-65105
漏洞归属组件:apptainer
漏洞归属的版本:1.1.6
CVSS评分:
BaseScore:5.3 Medium
Vector:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
漏洞简述:
Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor: and --security=selinux:

更多参考(点击展开)
参考来源 参考链接 来源链接
https://github.com/advisories/GHSA-fh74-hm69-rqjw
https://github.com/sylabs/singularity/commit/5af3e790c40593591dfc26d0692e4d4b21c29ba0
https://github.com/sylabs/singularity/security/advisories/GHSA-wwrx-w7c9-rf87
https://nvd.nist.gov/vuln/detail/CVE-2025-65105
https://github.com/apptainer/apptainer/pull/3226
https://github.com/sylabs/singularity/commit/27882963879a7af1699fd6511c3f5f1371d80f33
https://nvd.nist.gov/vuln/detail/CVE-2025-64750
https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm
https://security-tracker.debian.org/tracker/CVE-2025-65105
https://github.com/sylabs/singularity
https://bugzilla.redhat.com/show_bug.cgi?id=2418392
https://github.com/apptainer/apptainer/commit/4313b42717e18a4add7dd7503528bc15af905981
https://github.com/apptainer/apptainer
https://www.cve.org/CVERecord?id=CVE-2025-65105
https://github.com/apptainer/apptainer/commit/82f17900a0c31bc769bf9b4612d271c7068d8bf2
https://github.com/sylabs/singularity/pull/3850
https://github.com/apptainer/apptainer/security/advisories/GHSA-j3rw-fx6g-q46j
https://github.com/advisories/GHSA-j3rw-fx6g-q46j
https://www.mend.io/vulnerability-database/CVE-2025-65105

漏洞分析指导链接:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
漏洞数据来源:
七彩瞬析开源风险感知平台
漏洞补丁信息:

详情(点击展开)
影响的包 修复版本 修复补丁 问题引入补丁 来源
apptainer/apptainer https://github.com/apptainer/apptainer/commit/4313b42717e18a4add7dd7503528bc15af905981 ljqc
apptainer/apptainer https://github.com/apptainer/apptainer/commit/82f17900a0c31bc769bf9b4612d271c7068d8bf2 ljqc
https://github.com/sylabs/singularity/commit/5af3e790c40593591dfc26d0692e4d4b21c29ba0 osv
https://github.com/apptainer/apptainer/pull/3226 cvelistv5
https://github.com/sylabs/singularity/commit/27882963879a7af1699fd6511c3f5f1371d80f33 osv
https://github.com/apptainer/apptainer/commit/4313b42717e18a4add7dd7503528bc15af905981 cvelistv5
https://github.com/apptainer/apptainer/commit/82f17900a0c31bc769bf9b4612d271c7068d8bf2 cvelistv5
https://github.com/sylabs/singularity/pull/3850 osv

二、漏洞分析结构反馈
影响性分析说明:

openEuler评分:

受影响版本排查(受影响/不受影响):
1.master(1.1.6):
2.openEuler-20.03-LTS-SP4:
3.openEuler-22.03-LTS-SP3(1.1.6):
4.openEuler-22.03-LTS-SP4(1.1.6):
5.openEuler-24.03-LTS(1.1.6):
6.openEuler-24.03-LTS-Next(1.1.6):
7.openEuler-24.03-LTS-SP1(1.1.6):
8.openEuler-24.03-LTS-SP2(1.1.6):
9.openEuler-24.03-LTS-SP3(1.1.6):

修复是否涉及abi变化(是/否):
1.master(1.1.6):
2.openEuler-20.03-LTS-SP4:
3.openEuler-22.03-LTS-SP3(1.1.6):
4.openEuler-22.03-LTS-SP4(1.1.6):
5.openEuler-24.03-LTS(1.1.6):
6.openEuler-24.03-LTS-Next(1.1.6):
7.openEuler-24.03-LTS-SP1(1.1.6):
8.openEuler-24.03-LTS-SP2(1.1.6):
9.openEuler-24.03-LTS-SP3(1.1.6):

原因说明:
1.master(1.1.6):
2.openEuler-20.03-LTS-SP4:
3.openEuler-22.03-LTS-SP3(1.1.6):
4.openEuler-22.03-LTS-SP4(1.1.6):
5.openEuler-24.03-LTS(1.1.6):
6.openEuler-24.03-LTS-Next(1.1.6):
7.openEuler-24.03-LTS-SP1(1.1.6):
8.openEuler-24.03-LTS-SP2(1.1.6):
9.openEuler-24.03-LTS-SP3(1.1.6):

likedislike
openeuler-ci-botopeneuler-ci-bot成员
2025年12月3日 添加了   CVE/UNFIXED 标签
openeuler-ci-botopeneuler-ci-bot成员
2025年12月3日 创建了CVE和安全问题
openeuler-ci-bot
openeuler-ci-bot成员
2025年12月3日 评论:

Hi openeuler-ci-bot, welcome to the openEuler Community.
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here.
If you have any questions, please contact the SIG: sig-HPC, and any of the maintainers: @hejiancong557 , @iotwins , @luyao201

likedislike
openeuler-ci-botopeneuler-ci-bot成员
2025年12月3日 添加了   sig/sig-HPC 标签
openeuler-ci-bot
openeuler-ci-bot成员
2025年12月3日 评论:
参考网址 关联pr 状态 补丁链接
https://nvd.nist.gov/vuln/detail/CVE-2025-65105NoneNonehttps://github.com/apptainer/apptainer/commit/82f17900a0c31bc769bf9b4612d271c7068d8bf2
https://github.com/apptainer/apptainer/commit/4313b42717e18a4add7dd7503528bc15af905981
https://ubuntu.com/security/CVE-2025-65105NoneNonehttps://discourse.ubuntu.com/c/project
https://www.opencve.io/cve/CVE-2025-65105
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2025-65105
https://security-tracker.debian.org/tracker/CVE-2025-65105
http://www.cnnvd.org.cn/web/vulnerability/queryLds.tag?qcvCnnvdid=CVE-2025-65105

说明:补丁链接仅供初步排查参考,实际可用性请人工再次确认,补丁下载验证可使用CVE补丁工具。
若补丁不准确,烦请在此issue下评论 '/report-patch 参考网址 补丁链接1,补丁链接2' 反馈正确信息,便于我们不断优化工具,不胜感激。
如 /report-patch https://security-tracker.debian.org/tracker/CVE-2021-3997 https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1

likedislike
openeuler-ci-botopeneuler-ci-bot成员
2025年12月3日 修改了描述
此处折叠了13条事件消息 查看更多
openeuler-ci-botopeneuler-ci-bot成员
1月12日 修改了issue 的描述
chenyanpan
1月30日 评论:

❌ 自动修复失败

错误信息

应用 patch 失败: patch 应用失败: error: fs.h: does not exist in index
error: fuseprivate.c: does not exist in index
error: fuseprivate.h: does not exist in index
error: hl.c: does not exist in index
error: ll_main.c: does not exist in index
error: stat.c: does not exist in index

需要人工介入处理。


由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

❌ 自动修复失败

错误信息

应用 patch 失败: name 're' is not defined

需要人工介入处理。


由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

✅ 自动修复完成

分析结果

  • 根因: Apptainer 容器平台中,容器可以禁用两种形式的 --security 选项,这些选项原本用于限制容器操作,但被错误地允许非特权用户使用,导致安全限制被绕过。
  • 漏洞类型: 配置错误
  • 严重程度: Medium

修复信息

  • 提交: 80c95ed8
  • 受影响文件: 5 个

由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

✅ 自动修复完成

分析结果

  • 根因: Apptainer 容器平台在版本小于 1.4.5 的版本中,容器可以禁用两种形式的 --security 选项,这导致容器可以绕过默认的安全限制,从而可能执行未授权的操作。
  • 漏洞类型: 配置错误
  • 严重程度: Medium

修复信息

  • 提交: ed78b4e5
  • 受影响文件: 5 个

由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

❌ 自动修复失败

错误信息

Cmd('git') failed due to: exit code(128)
  cmdline: git push origin fix/issue-8-e9487a6b
  stderr: 'fatal: could not read Username for 'https://atomgit.com': Device not configured'

需要人工介入处理。


由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

✅ 自动修复完成

分析结果

  • 根因: Apptainer 容器平台中,存在一种安全选项 --security 的配置错误,允许容器禁用 AppArmor 和 SELinux 的安全策略,导致容器操作不受限制。
  • 漏洞类型: 配置错误
  • 严重程度: Medium

修复信息

  • 提交: 0d956969
  • 受影响文件: 5 个

由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

✅ 自动修复完成

分析结果

  • 根因: Apptainer 容器平台在版本小于 1.4.5 的版本中,容器可以禁用两种形式的 --security 选项,这些选项本应限制容器执行的操作,但未正确地限制非特权用户的能力。
  • 漏洞类型: 权限提升
  • 严重程度: Medium

修复信息

  • 提交: a18a2e86
  • 受影响文件: 5 个

由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

❌ 自动修复失败

错误信息

'GitConfig' object has no attribute 'base_branch'

需要人工介入处理。


由 openEuler Fixer 自动处理

likedislike
chenyanpan
1月30日 评论:

✅ 自动修复完成

分析结果

  • 根因: Apptainer版本低于1.4.5时,容器可以禁用两种形式的--security选项,这允许容器执行受限操作,尽管这些选项在文档中被提及为root用户的功能。
  • 漏洞类型: 配置错误
  • 严重程度: Medium

修复信息

  • 提交: 82cce8e1
  • 受影响文件: 5 个

由 openEuler Fixer 自动处理

likedislike
openeuler-ci-botopeneuler-ci-bot成员
3月10日 修改了issue 的描述
此处折叠了6条事件消息 查看更多
XXingSongSun
6月3日 关联了pull request:Fix CVE-2025-65105