Description
apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On 64-bit platforms an out-of-range value such as 4294967296 (2^32) is truncated to 0, and negative values wrap. Because apko parses the passwd and group entries supplied by the packages it installs and writes them back into the image, an attacker who controls a package installed into the image can ship an entry that appears to declare an unprivileged UID or GID but is written into the built image as UID 0 or GID 0 (root). The truncated UID is also used when resolving the image's run-as user. This issue has been fixed in version 1.4.5.
Published: 2026-10-05
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

Apko parses untrusted package supplied /etc/passwd and /etc/group entries with strconv.Atoi and casts the resulting integer to a 32‑bit unsigned value without checking the range. On 64‑bit systems values larger than 2^32−1 or negative numbers wrap or truncate to zero, so an entry that appears to have an unprivileged UID or GID may actually be stored as UID 0 or GID 0. This allows an attacker who can influence the package content to embed a user or group line that resolves to root in the built image, and the truncated UID is also used when deciding the image’s run‑as user. The practical result is that the container image will run with root privileges when executed.

Affected Systems

The vulnerability affects chainguard‑dev’s apko tooling, specifically all versions from 0.2.0 up to but not including 1.4.5. Any image built with an earlier apko release that installed content from untrusted packages is susceptible.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity risk, and the EPSS score is not available, suggesting the vulnerability is not currently highly exploited in the wild. It is not listed in the CISA KEV catalog. Attack feasibility requires the attacker to provide or modify a package that the maintainer will build into the image; once such a package is accepted, the image will contain root entries and run as root when deployed. This creates a clear privilege escalation path that could enable a container escape or host compromise if the container runtime does not enforce strict isolation.

Generated by OpenCVE AI on October 5, 2026 at 22:40 UTC.

Remediation

Vendor Solution

Upgrade to apko 1.4.5 or later, which rejects UID and GID values outside 0 to 4294967295 instead of truncating them. Images built with earlier versions from untrusted packages should be rebuilt.


OpenCVE Recommended Actions

  • Upgrade apko to version 1.4.5 or later, which validates UID and GID ranges instead of truncating them
  • Rebuild any images that were assembled with apko 0.2.0 through 1.4.4, ensuring no untrusted package supplies malformed UID/GID entries
  • If rebuild is not possible, avoid using packages that provide custom /etc/passwd or /etc/group entries or sanitize these entries before they are injected into the image

Generated by OpenCVE AI on October 5, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Chainguard-dev
Chainguard-dev apko
Vendors & Products Chainguard-dev
Chainguard-dev apko

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On 64-bit platforms an out-of-range value such as 4294967296 (2^32) is truncated to 0, and negative values wrap. Because apko parses the passwd and group entries supplied by the packages it installs and writes them back into the image, an attacker who controls a package installed into the image can ship an entry that appears to declare an unprivileged UID or GID but is written into the built image as UID 0 or GID 0 (root). The truncated UID is also used when resolving the image's run-as user. This issue has been fixed in version 1.4.5.
Title apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root
Weaknesses CWE-197
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Chainguard-dev Apko
cve-icon MITRE

Status: PUBLISHED

Assigner: chainguard

Published:

Updated: 2026-10-05T20:17:46.477Z

Reserved: 2026-10-05T19:21:04.930Z

Link: CVE-2026-105768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T21:16:35.913

Modified: 2026-10-05T21:16:36.027

Link: CVE-2026-105768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T23:15:18Z

Weaknesses