在 crun 中发现了一个缺陷。在 操作后,重新打开 作为标准输入/输出流时,可能会跟随符号链接,从而将宿主机的某个文件连接到容器的标准输入/输出流,并更改该文件的所有权。受影响的版本为 crun 1.29.1 及更早版本。在挂载全新 的默认配置下,该问题不会暴露。目前尚无修复版本发布。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84042 | 7.8 HIGH | Crun: crun: rootful krun with passt executes container payload as host root |
| CVE-2026-88770 | 6.5 MEDIUM | Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo |
| CVE-2026-88763 | 5.9 MEDIUM | Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o |
| CVE-2026-88264 | 5.6 MEDIUM | Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs |
No comments yet