Описание
ELSA-2026-19020: crun security update (MODERATE)
[1.27-2]
- enable krun handler for crun on RHEL 10
- Resolves: RHEL-161090
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
crun
1.27-2.el10_2
crun-krun
1.27-2.el10_2
Oracle Linux x86_64
crun
1.27-2.el10_2
crun-krun
1.27-2.el10_2
Связанные CVE
Связанные уязвимости
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
crun is an open source OCI Container Runtime fully written in C. In ve ...