An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within /run/singularity/instances/sing/<user>/<instance>. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.
{
"versions": [
{
"introduced": "3.1.0"
},
{
"fixed": "3.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.0-rc2"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11328.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "sle-15-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "sle-15-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.1"
}
]
}
]