CVE-2025-64750 Overview
CVE-2025-64750 affects SingularityCE and SingularityPRO, open source container platforms maintained by Sylabs. The vulnerability allows an attacker to redirect Linux Security Module (LSM) label write operations, rendering user-specified LSM restrictions ineffective. Exploitation requires the victim to run a malicious container image that redirects the mount of /proc to a shared mount destination controlled by the attacker. The flaw is categorized under [CWE-61] (UNIX Symbolic Link Following) and stems from unsafe procfs access when applying security options such as AppArmor profiles.
Critical Impact
An attacker who controls a shared mount and induces a user to run a malicious container can silently bypass LSM-based restrictions the user believed were enforcing containment.
Affected Products
- SingularityCE versions prior to 4.3.5
- SingularityPRO versions prior to 4.1.11
- SingularityPRO versions prior to 4.3.5
Discovery Timeline
- 2025-12-02 - CVE-2025-64750 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-64750
Vulnerability Analysis
SingularityCE and SingularityPRO apply LSM security labels, including AppArmor profiles, by writing to files under the container's /proc filesystem. When Singularity applies these labels, it does not validate that the target procfs path resolves to the expected kernel-managed pseudo-filesystem. An attacker who can influence the mount layout can substitute the destination of /proc with a shared mount whose contents they control. The LSM write operation then targets attacker-controlled storage instead of the kernel interface, and the intended security restriction is silently discarded.
Root Cause
The root cause is unsafe file operations against /proc inside a container namespace without using a race-safe, magic-link-aware procfs handle. Prior versions used ordinary path-based writes when applying AppArmor profiles, allowing symlink-style redirection through a shared mount overlay. The fix introduces the pathrs-lite/procfs interface for writing AppArmor profiles and additionally hardens --security option handling to fail closed when a requested option cannot be applied.
Attack Vector
Exploitation is local and requires user interaction. The attacker must (1) supply a malicious container image that redirects the container's /proc mount to a shared mount destination, and (2) control the contents of that shared mount, either by running a second malicious container that binds it or through host-side write access. When the victim runs the image, LSM label writes are diverted, and downstream operations proceed without the LSM policy the user requested.
// Security patch: internal/pkg/security/security.go
// fix: fail if --security options can't be applied
-// Copyright (c) 2018-2020, Sylabs Inc. All rights reserved.
+// Copyright (c) 2018-2025, Sylabs Inc. All rights reserved.
// This software is licensed under a 3-clause BSD license. Please consult the
// LICENSE.md file distributed with the sources of this project regarding your
// rights to use or distribute this software.
Source: Singularity Commit 2788296
// Security patch: internal/pkg/security/apparmor/apparmor_supported.go
// fix: use pathrs-lite/procfs when writing apparmor profile
-// Copyright (c) 2018-2022, Sylabs Inc. All rights reserved.
+// Copyright (c) 2018-2025, Sylabs Inc. All rights reserved.
// This software is licensed under a 3-clause BSD license. Please consult the
// LICENSE.md file distributed with the sources of this project regarding your
// rights to use or distribute this software.
Source: Singularity Commit 5af3e79
Detection Methods for CVE-2025-64750
Indicators of Compromise
- Container images that specify bind mounts redirecting /proc to a user-writable or shared mount path.
- Unexpected files matching AppArmor profile names appearing inside user-writable shared mount directories.
- Singularity invocations that succeed despite --security options that would normally fail on the host.
Detection Strategies
- Inspect Singularity container definition files and runtime arguments for --bind or overlay directives that target /proc.
- Audit host-side shared mounts accessible to Singularity workloads and flag those writable by unprivileged users.
- Correlate AppArmor profile load events with Singularity process launches to identify runs where a profile was requested but not registered by the kernel.
Monitoring Recommendations
- Log all execve calls to singularity and apptainer binaries with full argument capture for post-hoc review.
- Monitor /proc/*/attr/* and AppArmor kernel interfaces for writes originating from container runtime processes.
- Alert on Singularity version banners reporting SingularityCE below 4.3.5 or SingularityPRO below 4.1.11/4.3.5 in production inventories.
How to Mitigate CVE-2025-64750
Immediate Actions Required
- Upgrade SingularityCE to 4.3.5 or SingularityPRO to 4.1.11 or 4.3.5 on all hosts that execute untrusted container images.
- Inventory shared mounts exposed to multi-tenant Singularity users and restrict write access to trusted principals only.
- Reject or quarantine container images from untrusted sources until hosts are patched.
Patch Information
The vulnerability is fixed in SingularityCE 4.3.5 and SingularityPRO 4.1.11 and 4.3.5. The upstream fixes are commits 2788296 and 5af3e79, tracked in Singularity Pull Request #3850. Full advisory details are published in GHSA-wwrx-w7c9-rf87 and the related runc advisory GHSA-cgrx-mc8f-2prm.
Workarounds
- Avoid executing container images from untrusted publishers on hosts where LSM restrictions form part of the security boundary.
- Prohibit user-controlled bind mounts that target /proc when invoking Singularity.
- Disallow shared mounts writable by multiple tenants on hosts that run Singularity workloads with --security options.
# Verify installed Singularity version and upgrade if below fixed release
singularity --version
# Example: block user-supplied bind mounts targeting /proc via wrapper policy
# (deny any --bind argument whose destination is /proc or a subpath)
grep -E -- '--bind[= ][^ ]*:/proc(/|$| )' "$SINGULARITY_CMDLINE" \
&& { echo "Rejected: bind mount targeting /proc"; exit 1; }
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.