Container Configuration Flaw in crun Affects Red Hat Products
CVE-2026-88264
5.6MEDIUM
What is CVE-2026-88264?
A vulnerability exists in crun that can lead to unauthorized access if the container configuration does not have a dedicated mount for /dev. This flaw allows terminal setups to redirect /dev/console to an attacker-controlled path, particularly through the read-only-rootfs bind-mount fallback. Notably, configurations that utilize a fresh /dev mount are not vulnerable. Currently, no patches or fixes have been released to address this issue.