CVE-2026-105768
Deferred Deferred - Pending Action

Integer Underflow in apko Leading to Root Privilege Escalation

Vulnerability report for CVE-2026-105768, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: 82cea9a6-e9e3-46fe-bdb0-3673de380178

Description

apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On 64-bit platforms an out-of-range value such as 4294967296 (2^32) is truncated to 0, and negative values wrap. Because apko parses the passwd and group entries supplied by the packages it installs and writes them back into the image, an attacker who controls a package installed into the image can ship an entry that appears to declare an unprivileged UID or GID but is written into the built image as UID 0 or GID 0 (root). The truncated UID is also used when resolving the image's run-as user. This issue has been fixed in version 1.4.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
chainguard-dev apko 0.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-197 Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

apko is a tool for building OCI container images from apk packages. Between versions 0.2.0 and 1.4.5, it had a flaw in parsing UID and GID fields from /etc/passwd and /etc/group. The tool used strconv.Atoi to convert these values to uint32 without checking if they were within valid range. On 64-bit systems, values like 4294967296 (2^32) were truncated to 0, and negative values wrapped around. Attackers could exploit this by including malicious package entries that appear to set unprivileged UIDs or GIDs but instead set them to root (0) in the built image.

Detection Guidance

This vulnerability is specific to apko builds and requires checking for incorrect UID/GID parsing in /etc/passwd or /etc/group files within container images. Inspect container images built with apko versions before 1.4.5 for entries with UID/GID values that are out of range (e.g., 4294967296 or negative values). Use commands like 'apko version' to check the apko version and 'docker inspect <image>' to examine image metadata for suspicious UID/GID entries.

Impact Analysis

If you use apko versions 0.2.0 to 1.4.5 to build container images, an attacker who controls a package in your image could escalate privileges. They could make a service or process run as root (UID 0) even if it was intended to run as an unprivileged user. This could allow the attacker to gain full control over the container or host if the container has sufficient privileges.

Compliance Impact

This vulnerability could lead to unauthorized privilege escalation, potentially violating compliance requirements that mandate least-privilege access controls. For example, GDPR requires appropriate security measures to protect personal data, and HIPAA requires access controls to safeguard protected health information. Unauthorized root access could result in data breaches or non-compliance with these regulations.

Mitigation Strategies

Upgrade apko to version 1.4.5 or later to address the UID/GID parsing issue. Review installed packages for malicious entries in /etc/passwd or /etc/group that may set UID/GID to 0. Verify image configurations to ensure run-as users are correctly resolved.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105768. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart