crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
CVSS Details
- CVSS 3.1 Base Score: 0
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade crun | Apr 7, 2026 | Apr 6, 2026 |
| Alpine Linux | — | Upgrade crun | Mar 27, 2026 | Mar 25, 2026 |
| Oracle_linux | — | Upgrade crun | Apr 22, 2026 | Mar 25, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Mar 25, 2026 |
| Redhat_linux | — | Upgrade container-selinuxUpgrade crunUpgrade crun-debugsourceUpgrade crun-debuginfoUpgrade crun-krun | Apr 7, 2026 | Mar 25, 2026 |
| Rocky_linux | — | Upgrade crunUpgrade crun-debugsourceUpgrade crun-debuginfo | Apr 10, 2026 | Apr 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub