Executive brief
Apptainer, a container platform for high-performance computing, contains a flaw in how it restricts where containers can be run. Administrators use a specific setting to ensure containers only execute from approved, 'safe' directories; however, due to a naming error, the system may accidentally allow containers to run from unapproved folders that have similar names. This could allow users to bypass security policies and run unauthorized software on the system.
Technical details
A path validation vulnerability exists in Apptainer's 'limit container paths' directive within apptainer.conf. When operating in setuid mode, the software performs incorrect string matching on directory paths, failing to account for trailing slashes or boundary characters. For example, a restriction intended for '/data/safe' would incorrectly match and permit execution from '/data/safe-but-unsafe'. An attacker with local access could exploit this to run containers from unauthorized locations, bypassing administrative execution policies. This issue is resolved in version 1.5.1.
Affected products
- Apptainer Apptainer < 1.5.1
Timeline
- 2026-06-26: advisory: GitHub Advisory published
- 2026-06-26: disclosed
- 2026-06-04: patched: Version 1.5.1 released