VDB

CVE-2026-47766

CVE-2026-47766 PUBLISHED CVSS 5.1 MEDIUM

Reported by GitHub_M · Published August 14, 2026

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/dev`, crun follows that symlink and creates the default device nodes and stdio symlinks at the symlink target outside the container rootfs. In a local rootful crun replay, this created fixed device nodes and symlinks outside the rootfs before crun returned failure. A pre-existing file named `ptmx` in the target directory was also replaced by crun's forced `ptmx -> pts/ptmx` symlink. Version 1.28 fixes the issue.

Risk Scores

CVSS 4.0
5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
containerscrun< 1.28
containerscrun< 1.28
alpinecrun0, 0, 0

Timeline

  • Jun 15, 2026 CVE Published
  • Aug 24, 2026 EPSS Score
  • Aug 27, 2026 EPSS Score
  • Sep 6, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›