CVE-2026-88265: Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown

Published Sep 10, 2026
·
Updated

A flaw was found in crun. After pivotroot or chroot, crun reopens /dev/null for stdio without preventing symlink follows. If /dev is not mounted and a malicious image replaces /dev/null with a symlink, crun can open a host bind-mounted file and a non-root container process can write to it and chown it. Affected versions are crun 1.29.1 and earlier. This is a separate issue from CVE-2026-47766 and from the /dev/console symlink flaw. No fixed release is published yet.

Other sources

A flaw was found in crun. After pivotroot, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

MITRE

Affected Software

1 affected component
Crun crun<=1.29.1

Event History

Sep 10, 2026
Data Sourced
via Red Hat·01:57 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·08:57 AM
Data Sourced
via MITRE·08:57 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Are standard container deployments affected?

Default configurations that mount a fresh /dev are not exposed. The issue requires a setup where /dev is not mounted after pivot_root or chroot.

2

What conditions are required for exploitation?

A malicious image must be able to replace /dev/null with a symlink. The symlink must resolve to a host file that is bind-mounted into the container, allowing a non-root container process to write to that file and change its ownership.

3

Which crun versions are affected and is a fix available?

crun 1.29.1 and earlier are affected. No fixed release has been published.

4

What can be done while no fixed release is available?

Use configurations that mount a fresh /dev, which are described as not exposed. Avoid running untrusted images in configurations where /dev is absent and an image can control /dev/null.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203