CVE-2026-84042

Summary

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-269: Improper Privilege Management

Workarounds

Do not run untrusted images with krun and passt until a fixed crun is released.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References