Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Has fix for CVE-2021-33622 been propagated? #586

Closed
nileshpatra opened this issue Feb 20, 2022 · 2 comments
Closed

Has fix for CVE-2021-33622 been propagated? #586

nileshpatra opened this issue Feb 20, 2022 · 2 comments
Labels
question Further information is requested

Comments

@nileshpatra
Copy link
Contributor

nileshpatra commented Feb 20, 2022

Note: We encourage questions about usage of SingularityCE to be made via the Google Group or Slack channels [..]
See: https://sylabs.io/resources/community for links.

I would have done this, but that link gives me a "Page not found"

Type of issue
Question regarding fix for CVE-2021-33622

Description of issue
It is written that this issue has been fixed in PRO edition, but there has been no mention of this being fixed in CE edition -- wanted to enquire if it has been fixed in later versions(as the report mentions version 3.5.x-3.6.x)? There is no mention about this CVE fixing in the changelog either. Any answer is appreciated

@dtrudg
Copy link
Member

dtrudg commented Feb 21, 2022

A fix for CVE-2021-33622 was only released for SingularityPRO 3.5 because the precise issue covered by that CVE was not present in Singularity 3.7, which was the supported open source release at that time. Open source Singularity 3.5.x - 3.6.x were affected by this CVE, but we only support and provide fixes for the latest open source SingularityCE version, which was 3.7 at the time. There is no patch and no changelog entry for the CVE as it was not present in 3.7.

A similar, but different, issue was present in open-source 3.7 as CVE-2021-32635. This was fixed in release 3.7.4 - see GHSA-5mv9-q7fq-9394

I'll ensure the community link is fixed. Thanks. See https://sylabs.io/singularity#community

@dtrudg dtrudg added the question Further information is requested label Feb 21, 2022
@dtrudg
Copy link
Member

dtrudg commented Feb 21, 2022

Note that this information was communicated on the SingularityCE mailing list at the time the issue was dealt with (June 9th 2021)

https://groups.google.com/g/singularity-ce/c/OSK5BIHSkbE/m/6dc0DEMiAgAJ

I strongly advise joining the list / google group if you are using SingularityCE in production.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants