Crun
Containers · 4 CVEs
CVE-2026-88264
MEDIUM
Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs
Sep 10, 2026
CVE-2026-47766
MEDIUM
crun follows rootfs /dev symlink while creating default devices
Aug 14, 2026
CVE-2026-30892
HIGH
Crun incorrectly parses `crun exec` option `-u`, leading to privilege escalation
Mar 25, 2026
CVE-2025-24965
HIGH
.krun_config.json symlink attack creates or overwrites file on the host in crun
Feb 19, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-88264 | Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs | MEDIUM | 0.12% | Sep 10, 2026 |
| CVE-2026-47766 | crun follows rootfs /dev symlink while creating default devices | MEDIUM | 0.20% | Aug 14, 2026 |
| CVE-2026-30892 | Crun incorrectly parses `crun exec` option `-u`, leading to privilege escalation | HIGH | 0.17% | Mar 25, 2026 |
| CVE-2025-24965 | .krun_config.json symlink attack creates or overwrites file on the host in crun | HIGH | 0.58% | Feb 19, 2025 |
Showing 1 to 4 of 4 CVEs