GO-2025-4177
Singularity ineffectively applies of selinux / apparmor LSM process labels in github.com/sylabs/singularity
Details
Singularity ineffectively applies of selinux / apparmor LSM process labels in github.com/sylabs/singularity.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/sylabs/singularity/v4 before v4.1.11.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for github.com/sylabs/singularity (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/sylabs/singularity/v4 (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/sylabs/singularity/security/advisories/GHSA-wwrx-w7c9-rf87[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-64750[ADVISORY]
- https://github.com/sylabs/singularity/commit/27882963879a7af1699fd6511c3f5f1371d80f33[FIX]
- https://github.com/sylabs/singularity/commit/5af3e790c40593591dfc26d0692e4d4b21c29ba0[FIX]
- https://github.com/sylabs/singularity/pull/3850[FIX]
- https://github.com/advisories/GHSA-fh74-hm69-rqjw[WEB]
- https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm[WEB]