Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88265

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

Отчет

This Moderate flaw in crun allows a non-root container process to write to and change ownership of a host bind-mounted file. Exploitation requires a malicious container image to replace /dev/null with a symlink while /dev is not mounted within the container, indicating specific preconditions for successful attack.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened ImagescrunAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2531224crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown

EPSS

Процентиль: 2%
0.00119
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
5 дней назад

(A flaw was found in crun. After pivot_root, reopening /dev/null for st ...)

CVSS3: 5.6
nvd
6 дней назад

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

CVSS3: 5.6
debian
6 дней назад

A flaw was found in crun. After pivot_root, reopening /dev/null for st ...

CVSS3: 5.6
github
6 дней назад

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

EPSS

Процентиль: 2%
0.00119
Низкий

5.6 Medium

CVSS3