GHSA-x6ph-r535-3vjw
apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files
Quick fix
GHSA-x6ph-r535-3vjw — chainguard.dev/apko: upgrade to the fixed version with the command below.
go get chainguard.dev/apko@v0.29.5Details
It was discovered that the ld.so.cache in images generated by apko had file system permissions mode `0666`: ``` bash-5.3# find / -type f -perm -o+w /etc/ld.so.cache ```
This issue was introduced in commit [04f37e2 ("generate /etc/ld.so.cache (#1629)")](https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9)([v0.27.0](https://github.com/chainguard-dev/apko/releases/tag/v0.27.0)).
### Impact This potentially allows a local unprivileged user to add additional additional directories including dynamic libraries to the dynamic loader path. A user could exploit this by placing a malicious library in a directory they control.
### Patches This issue was addressed in apko in [aedb077 ("fix: /etc/ld.so.cache file permissions (#1758)")](https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3) ([v0.29.5](https://github.com/chainguard-dev/apko/releases/tag/v0.29.5)).
### Acknowledgements
Many thanks to Cody Harris from [H2O.ai](http://h2o.ai/) for reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/chainguard-dev/apko/security/advisories/GHSA-x6ph-r535-3vjw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-53945[ADVISORY]
- https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9[WEB]
- https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3[WEB]
- https://github.com/chainguard-dev/apko[PACKAGE]
- https://github.com/chainguard-dev/apko/releases/tag/v0.29.5[WEB]