crun 中存在一个缺陷。当 crun 使用 libkrun 编译,并以需要 root 权限的方式启动容器且启用 passt 网络(krun.use_passt)时,crun 可以以宿主机的 root 权限执行来自容器镜像的攻击者可控的载荷(payload)。该问题是在 crun 1.29 中引入的回归(regression),影响 crun >= 1.29 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88770 | 6.5 MEDIUM | Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo |
| CVE-2026-88763 | 5.9 MEDIUM | Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o |
| CVE-2026-88265 | 5.6 MEDIUM | Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and |
| CVE-2026-88264 | 5.6 MEDIUM | Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs |
No comments yet