Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84042— Crun: crun: rootful krun with passt executes container payload as host root

Quick assessment

Affected
Red Hat Red Hat Hardened Images
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

crun 中存在一个缺陷。当 crun 使用 libkrun 编译,并以需要 root 权限的方式启动容器且启用 passt 网络(krun.use_passt)时,crun 可以以宿主机的 root 权限执行来自容器镜像的攻击者可控的载荷(payload)。该问题是在 crun 1.29 中引入的回归(regression),影响 crun >= 1.29 版本。

CVSS 7.8 · High

Possible ATT&CK Techniques 1 AI

T1069 · Permission Groups Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84042

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Crun: crun: rootful krun with passt executes container payload as host root
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1

II. Public POCs for CVE-2026-84042

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84042

登录查看更多情报信息。

Other References for CVE-2026-84042 (3)

Same Patch Batch · Red Hat · 2026-09-10 · 5 CVEs total

CVE-2026-88770 6.5 MEDIUM Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo
CVE-2026-88763 5.9 MEDIUM Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o
CVE-2026-88265 5.6 MEDIUM Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and
CVE-2026-88264 5.6 MEDIUM Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs

IV. Related Vulnerabilities

V. Comments for CVE-2026-84042

No comments yet


Leave a comment