Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105768— apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root

Quick assessment

Affected
chainguard-dev apko
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

apko 允许用户构建并发布由 APK 软件包生成的 OCI 容器镜像。在 0.2.0 至 1.4.5 版本之前, 模块中的 和 函数在处理 和 条目中的 UID 和 GID 字段时,使用了 将其转换为 类型,但未进行范围检查。在 64 位平台上,超出范围的数值(例如 4294967296,即 2^32)会被截断为 0,而负数值则会发生回绕(wrap-around)。 由于 apko 会解析其所安装软件包提供的 passwd 和 group 条目,并将其写回镜像中,因此,如果攻击者控制了某个被安装到镜像中的软件包,

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105768

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root
Source: CVE Program / CVE List V5
Vulnerability Description
apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On 64-bit platforms an out-of-range value such as 4294967296 (2^32) is truncated to 0, and negative values wrap. Because apko parses the passwd and group entries supplied by the packages it installs and writes them back into the image, an attacker who controls a package installed into the image can ship an entry that appears to declare an unprivileged UID or GID but is written into the built image as UID 0 or GID 0 (root). The truncated UID is also used when resolving the image's run-as user. This issue has been fixed in version 1.4.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
数值截断错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
chainguard-dev apko 0.2.0 ~ 1.4.5 -

II. Public POCs for CVE-2026-105768

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105768

请登录查看更多情报信息。

Other References for CVE-2026-105768 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105768

No comments yet


Leave a comment