Impact
Apko parses untrusted package supplied /etc/passwd and /etc/group entries with strconv.Atoi and casts the resulting integer to a 32‑bit unsigned value without checking the range. On 64‑bit systems values larger than 2^32−1 or negative numbers wrap or truncate to zero, so an entry that appears to have an unprivileged UID or GID may actually be stored as UID 0 or GID 0. This allows an attacker who can influence the package content to embed a user or group line that resolves to root in the built image, and the truncated UID is also used when deciding the image’s run‑as user. The practical result is that the container image will run with root privileges when executed.
Affected Systems
The vulnerability affects chainguard‑dev’s apko tooling, specifically all versions from 0.2.0 up to but not including 1.4.5. Any image built with an earlier apko release that installed content from untrusted packages is susceptible.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity risk, and the EPSS score is not available, suggesting the vulnerability is not currently highly exploited in the wild. It is not listed in the CISA KEV catalog. Attack feasibility requires the attacker to provide or modify a package that the maintainer will build into the image; once such a package is accepted, the image will contain root entries and run as root when deployed. This creates a clear privilege escalation path that could enable a container escape or host compromise if the container runtime does not enforce strict isolation.
OpenCVE Enrichment