Container Configuration Flaw in crun Affects Red Hat Products
CVE-2026-88264

5.6MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88264?

A vulnerability exists in crun that can lead to unauthorized access if the container configuration does not have a dedicated mount for /dev. This flaw allows terminal setups to redirect /dev/console to an attacker-controlled path, particularly through the read-only-rootfs bind-mount fallback. Notably, configurations that utilize a fresh /dev mount are not vulnerable. Currently, no patches or fixes have been released to address this issue.

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.