A fast, lightweight OCI container runtime, used as an alternative to runc.
Version: 1.30.1
Type: Runtime
License:
| Expand | CVE | Title | Status | Sev |
|---|---|---|---|---|
| CVE-2026-30892 Open CVE-2026-30892 in a new tab | Crun incorrectly parses `crun exec` option `-u`, leading to privilege escalation | Not affected | Unknown | |
| CVE-2026-47766 Open CVE-2026-47766 in a new tab | crun follows rootfs /dev symlink while creating default devices | Not affected | Unknown | |
| CVE-2026-88264 Open CVE-2026-88264 in a new tab | Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs | Not affected | Unknown | |
| CVE-2026-88265 Open CVE-2026-88265 in a new tab | Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown | Not affected | Unknown |
Crun incorrectly parses `crun exec` option `-u`, leading to privilege escalation
crun follows rootfs /dev symlink while creating default devices
Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs
Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown