Generated remediation guidance and an executive summary. No account required.
Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1.
Cite this page
CVE-2023-38496. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2023-38496
Use CWE-269, Lfprojects vendor hub and Apptainer product page to widen CVE-2023-38496 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-30549 and CVE-2025-65105 for nearby disclosures in the same product family.