Symlink Vulnerability in Crun Container Tool from Red Hat
CVE-2026-88265

5.6MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88265?

A symlink vulnerability exists in the Crun container tool where, after a pivot_root operation, it improperly reopens /dev/null for standard input/output. This flaw allows malicious actors to follow a symlink leading to a host file, subsequently attaching it to the container's standard I/O, and changing the ownership of that file. This affects Crun versions up to 1.29.1, leaving containers potentially exposed. Default configurations utilizing a fresh /dev mount are not vulnerable. Currently, there is no fixed release available.

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.