{"id":"CVE-2025-53945","aliases":["GHSA-x6ph-r535-3vjw","GO-2025-3816"],"url":"https://o3.security/vulnerability/CVE-2025-53945","summary":"apko has incorrect permission (0666) in /etc/ld.so.cache and other files","details":"It was discovered that the ld.so.cache in images generated by apko had file system permissions mode `0666`:\n```\nbash-5.3# find / -type f -perm -o+w\n/etc/ld.so.cache\n```\n\nThis issue was introduced in commit [04f37e2 (\"generate /etc/ld.so.cache (#1629)\")](https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9)([v0.27.0](https://github.com/chainguard-dev/apko/releases/tag/v0.27.0)).\n\n###  Impact\nThis potentially allows a local unprivileged user to add additional additional directories including dynamic libraries to the dynamic loader path. A user could exploit this by placing a malicious library in a directory they control.\n\n### Patches\nThis issue was addressed in apko in [aedb077 (\"fix: /etc/ld.so.cache file permissions (#1758)\")](https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3) ([v0.29.5](https://github.com/chainguard-dev/apko/releases/tag/v0.29.5)).\n\n### Acknowledgements\n\nMany thanks to Cody Harris from [H2O.ai](http://h2o.ai/) for reporting this issue.","published":"2025-07-18T15:35:17.325Z","modified":"2026-08-12T03:51:36.178174262Z","cvss":{"score":7,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L"},"epss":{"score":0.00125,"percentile":0.02546,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"chainguard.dev/apko","fixedVersion":"0.29.5"}],"fix":{"url":"https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9","label":"chainguard-dev/apko@04f37e2"},"references":[{"type":"WEB","url":"https://github.com/chainguard-dev/apko/releases/tag/v0.27.0"},{"type":"WEB","url":"https://github.com/chainguard-dev/apko/releases/tag/v0.29.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53945.json"},{"type":"ADVISORY","url":"https://github.com/chainguard-dev/apko/security/advisories/GHSA-x6ph-r535-3vjw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53945"},{"type":"FIX","url":"https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9"},{"type":"FIX","url":"https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3"},{"type":"PACKAGE","url":"https://github.com/chainguard-dev/apko"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.178174262Z"}}