CVE-2019-11328: Fedoraproject Fedora

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.

Affected products

  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Opensuse Backports: version sle-15 only
  • Opensuse Leap: version 15.1 only
  • Sylabs Singularity: from 3.1.0, before 3.2.0 (fixed in 3.2.0); version 3.2.0 only

Published 2019-05-14. Last modified 2026-06-17.