Impact
The flaw originates from a bug in the Singularity configuration processor that validates the 'limit container paths' directive. The validator incorrectly treats sibling directories as matches when evaluating the whitelist; for example, if /data/safe is permitted, a path such as /data/safe-but-unsafe is considered acceptable. A local user can run a container image located in that sibling directory while the binary executes in setuid mode, thereby gaining the setuid privileges. This bypasses the administrator‑configured allowlist and lets a non‑privileged user launch containers with elevated privileges, effectively turning the path restriction into a no‑op. The weakness is a path traversal style vulnerability, classified as CWE‑22.
Affected Systems
Vulnerable versions are SingularityCE prior to 4.4.2 and SingularityPRO prior to 4.3.9 (and 4.1.14). Installations that do not enable the limit container paths feature are unaffected. The issue affects systems that use the Sylabs Singularity platforms, including SingularityPRO and the open‑source SingularityCE.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user that can launch containers in setuid mode; the attacker must have the ability to supply a container image and construct a path that falls outside the allowed list. Once the container runs, it inherits the privileges of the setuid executables, giving the attacker unauthorized system access. Because the exploit surface is limited to configurations that enable the limit container paths directive, careful review of the directive’s usage can mitigate risk.
OpenCVE Enrichment
Github GHSA