CVE-2025-65105

Description

A flaw was found in Apptainer. This vulnerability allows a container to disable the --security=apparmor: and --security=selinux:

Statement

This vulnerability is rated Moderate for Red Hat because Apptainer, when running containers on RHEL-based systems with SELinux enabled, allows a container to bypass the intended security restrictions provided by the --security=selinux option. This could lead to a reduction in the security posture of the container, even when the option is explicitly used.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Access Control

Technical Impact: Modify Memory; Read Memory; Execute Unauthorized Code or Commands; Gain Privileges or Assume Identity; Bypass Protection Mechanism; Other

Frequently Asked Questions

Want to get errata notifications? Sign up here.