PT-2025-48736 · Unknown · Singularitypro+1

Published

2021-05-27

·

Updated

2025-12-15

·

CVE-2025-64750

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions SingularityCE versions prior to 4.3.5 SingularityPRO versions prior to 4.1.11 and 4.3.5
Description SingularityCE and SingularityPRO are open source container platforms. If a user depends on LSM restrictions to prevent harmful actions, an attacker can redirect the LSM label write operation, making it ineffective under specific conditions. The attacker needs to make a user run a malicious container image that redirects the mount of /proc to the destination of a shared mount, which could be pre-configured on the target system or specified by the user when running the container. The attacker must also control the content of the shared mount, potentially through another malicious container or by having relevant permissions on the host system where it is bound.
Recommendations Update SingularityCE to version 4.3.5 or later. Update SingularityPRO to version 4.1.11 or 4.3.5 or later.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2025-64750
GHSA-CGRX-MC8F-2PRM
GHSA-FH74-HM69-RQJW
GHSA-WWRX-W7C9-RF87
GO-2025-4177
SUSE-SU-2025:4395-1

Affected Products

Singularity
Singularitypro