Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-87947
HistoryOct 10, 2022 - 12:00 a.m.

Singularity Image Format Encryption Problem Vulnerability

2022-10-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
singularity
image format
encryption
vulnerability
squashfs
cryptographic
hash
digital signatures
bypass

EPSS

0.002

Percentile

59.3%

Singularity Image Format is a compressed squashfs file system from Singularity that has a block organization structure, including metadata and definition files for containers, first labels, partition contents, signatures (if they exist), and, of course, the containers for the binaries themselves. Versions of Singularity Image Format prior to 2.8.1 are vulnerable to cryptographic issues, stemming from a vulnerability in the “github.com/sylabs/sif/v2/pkg/integrity” package that does not validate the hash used when verifying digital signatures. algorithm is secure. An attacker could exploit the vulnerability to bypass digital signatures.