Protection mechanism failure in Apptainer - CVE-2025-65105

 

Protection mechanism failure in Apptainer - CVE-2025-65105

Published: December 3, 2025


Vulnerability identifier: #VU119105
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-65105
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures using the "--security" option. A local user can bypass implemented security restrictions and perform otherwise restricted actions.


Affected software

Apptainer
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
HPC Module
openSUSE Leap
libsquashfuse0
squashfuse-debugsource
libsquashfuse0-debuginfo
squashfuse
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
squashfuse-tools
apptainer
apptainer-debuginfo
apptainer-sle16
apptainer-sle15_6
apptainer-leap
apptainer-sle15_7

How to mitigate CVE-2025-65105

Install updates from vendor's website.

Apptainer - update to 1.4.5
libsquashfuse0 - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
apptainer - update to 1.4.5-150600.4.12.1
apptainer-debuginfo - update to 1.4.5-150600.4.12.1
apptainer-sle16 - update to 1.4.5-150600.4.12.1
apptainer-sle15_6 - update to 1.4.5-150600.4.12.1
apptainer-leap - update to 1.4.5-150600.4.12.1
apptainer-sle15_7 - update to 1.4.5-150600.4.12.1

External References

Related Security Bulletins