Search CVE reports


Toggle filters

1 – 8 of 8 results


CVE-2026-88265

Medium priority
Needs evaluation

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default...

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-88264

Medium priority
Needs evaluation

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback....

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84042

Medium priority
Needs evaluation

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges....

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-47766

Medium priority
Needs evaluation

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as...

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-30892

Medium priority
Needs evaluation

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have...

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-24965

Medium priority
Needs evaluation

crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host....

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-27650

Medium priority
Needs evaluation

A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux...

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-18837

Medium priority

Not in release

An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c...

1 affected package

crun

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
crun Not in release
Show less packages