This vulnerability is in umoci but it was found that singularity is also affected. A dependency used by Singularity to extract docker/OCI image layers can be tricked into modifying host files by creating a malicious layer that has a symlink with the name "." (or "/"), when running as root. This vulnerability affects a singularity build or singularity pull as root, from a docker or OCI source, as well as the implicit build to SIF that occurs through root use of run/exec/shell against a malicious docker/OCI image URI. Reference: https://github.com/hpcng/singularity/releases
Created singularity tracking bugs for this issue: Affects: epel-all [bug 1952676] Affects: fedora-all [bug 1952675]
This is being addressed in #1946970
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.