apko has incorrect permission (0666) in /etc/ld.so.cache and other files
Vulnerability Description
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53945
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/chainguard-dev/apko/security/advisories/GHSA-x6ph-r535-3vjw
- https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9
- https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3
- https://github.com/chainguard-dev/apko/releases/tag/v0.27.0
- https://github.com/chainguard-dev/apko/releases/tag/v0.29.5
Affected Vendor
chainguard-dev
View all reports →