Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19020

Опубликовано: 08 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-19020: crun security update (MODERATE)

[1.27-2]

  • enable krun handler for crun on RHEL 10
  • Resolves: RHEL-161090

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

crun

1.27-2.el10_2

crun-krun

1.27-2.el10_2

Oracle Linux x86_64

crun

1.27-2.el10_2

crun-krun

1.27-2.el10_2

Связанные CVE

Связанные уязвимости

ubuntu
4 месяца назад

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.

CVSS3: 7.8
redhat
4 месяца назад

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.

nvd
4 месяца назад

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.

debian
4 месяца назад

crun is an open source OCI Container Runtime fully written in C. In ve ...

rocky
4 месяца назад

Moderate: crun security update