Описание
ELSA-2026-6621: crun security update (MODERATE)
[1.27-1]
- update to https://github.com/containers/crun/releases/tag/1.27
- fixes CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the --user option [rhel-9.7.z]
- Resolves: RHEL-161439
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
crun
1.27-1.el9_7
Oracle Linux x86_64
crun
1.27-1.el9_7
Связанные CVE
Связанные уязвимости
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
crun is an open source OCI Container Runtime fully written in C. In ve ...