Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor:<profile> and --security=selinux:<label> which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as being a feature for the root user, although these forms do also work for unprivileged users on systems where the corresponding feature is enabled. Apparmor is enabled by default on Debian-based distributions and SElinux is enabled by default on RHEL-based distributions, but on SUSE it depends on the distribution version. This vulnerability is fixed in 1.4.5.

Project Subscriptions

Vendors Products
Lfprojects Subscribe
Apptainer Subscribe
Enterprise Linux Subscribe
Singularity Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j3rw-fx6g-q46j Apptainer ineffectively applies selinux and apparmor --security options
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Dec 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 05 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:lfprojects:apptainer:*:*:*:*:*:go:*:*

Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian linux
Lfprojects
Lfprojects apptainer
Redhat
Redhat enterprise Linux
Sylabs
Sylabs singularity
Vendors & Products Debian
Debian linux
Lfprojects
Lfprojects apptainer
Redhat
Redhat enterprise Linux
Sylabs
Sylabs singularity

Tue, 02 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
Description Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor:<profile> and --security=selinux:<label> which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as being a feature for the root user, although these forms do also work for unprivileged users on systems where the corresponding feature is enabled. Apparmor is enabled by default on Debian-based distributions and SElinux is enabled by default on RHEL-based distributions, but on SUSE it depends on the distribution version. This vulnerability is fixed in 1.4.5.
Title Apptainer ineffective application of selinux and apparmor --security options
Weaknesses CWE-61
CWE-706
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-02T18:46:30.677Z

Reserved: 2025-11-17T20:55:34.693Z

Link: CVE-2025-65105

cve-icon Vulnrichment

Updated: 2025-12-02T18:44:08.681Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T18:15:48.947

Modified: 2025-12-05T19:08:58.887

Link: CVE-2025-65105

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-02T17:49:17Z

Links: CVE-2025-65105 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-12-04T16:44:39Z

Weaknesses