VDB
CVE-2026-30892
CVE-2026-30892
PUBLISHED
CVSS 7.800000190734863 HIGH
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
EPSS 0.02% · 4.3th percentile
Risk Scores
CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.02%
4.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| crun_project | crun | 1.19, 1.19, 1.19 |
| containers | crun | >= 1.19, < 1.27, >= 1.19, < 1.27, >= 1.19, < 1.27 |
Timeline
- Mar 25, 2026 CVE Published
- Mar 26, 2026 Coalition ESS Score
- Mar 26, 2026 CVE Updated
- Apr 6, 2026 Distribution Patch
- Apr 6, 2026 Security Advisory
- Apr 6, 2026 Distribution Patch
- Apr 6, 2026 Security Advisory
- Apr 6, 2026 Security Advisory
- Apr 8, 2026 Distribution Patch
- Apr 9, 2026 Distribution Patch
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score