Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-30892

Опубликовано: 26 мар. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the crun exec option -u (--user) is incorrectly parsed. The value 1 is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:crun_project:crun:*:*:*:*:*:*:*:*
Версия от 1.19 (включая) до 1.27 (исключая)

EPSS

Процентиль: 5%
0.00159
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

ubuntu
4 месяца назад

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.

CVSS3: 7.8
redhat
4 месяца назад

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.

debian
4 месяца назад

crun is an open source OCI Container Runtime fully written in C. In ve ...

rocky
4 месяца назад

Moderate: crun security update

rocky
4 месяца назад

Moderate: crun security update

EPSS

Процентиль: 5%
0.00159
Низкий

7.8 High

CVSS3

Дефекты

CWE-269