Skip to content

Has CVE-2023-30549 been fixed for singularity? #1969

Closed Answered by dtrudg
nileshpatra asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @nileshpatra - we consider that CVE-2023-30549 is fundamentally a duplicate of a kernel filesystem bug, that should be fixed by updating or patching the kernel. For Debian that underlying bug would be: https://security-tracker.debian.org/tracker/CVE-2022-1184

Sylabs has a detailed response to the Apptainer CVE here: https://sylabs.io/2023/04/response-to-cve-2023-30549/

We do not disable kernel mounts by default (like Apptainer has), because the underlying filesystem vulnerability has been fixed in the upstream/LTS kernel, and many users rely on overlay support in SingularityCE.

We would recommend that packagers / admins read the blog post linked above. They should consider whether thei…

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by dtrudg
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #1968 on August 01, 2023 13:55.