Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84042 2 Containers, Redhat 3 Crun, Hardened Images, Hummingbird 2026-09-13 7.8 High
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29
CVE-2026-88264 2 Containers, Redhat 3 Crun, Hardened Images, Hummingbird 2026-09-13 5.6 Medium
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.