PT-2025-48736 · Unknown · Singularitypro+1
Published
2021-05-27
·
Updated
2025-12-15
·
CVE-2025-64750
CVSS v4.0
7.3
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
SingularityCE versions prior to 4.3.5
SingularityPRO versions prior to 4.1.11 and 4.3.5
Description
SingularityCE and SingularityPRO are open source container platforms. If a user depends on LSM restrictions to prevent harmful actions, an attacker can redirect the LSM label write operation, making it ineffective under specific conditions. The attacker needs to make a user run a malicious container image that redirects the mount of
/proc to the destination of a shared mount, which could be pre-configured on the target system or specified by the user when running the container. The attacker must also control the content of the shared mount, potentially through another malicious container or by having relevant permissions on the host system where it is bound.Recommendations
Update SingularityCE to version 4.3.5 or later.
Update SingularityPRO to version 4.1.11 or 4.3.5 or later.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Singularity
Singularitypro