在 crun 中发现了一个缺陷。当容器配置未为 指定独立挂载时,终端设置(terminal setup)可能将 重定向到由攻击者控制的路径,包括通过只读根文件系统(read-only-rootfs)的 bind-mount 回退机制。受影响的版本为 crun 1.29.1 及更早版本。默认配置中挂载全新 的情况不受影响。目前尚无已发布的修复版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84042 | 7.8 HIGH | Crun: crun: rootful krun with passt executes container payload as host root |
| CVE-2026-88770 | 6.5 MEDIUM | Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo |
| CVE-2026-88763 | 5.9 MEDIUM | Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o |
| CVE-2026-88265 | 5.6 MEDIUM | Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and |
No comments yet