REDHAT-BUG-2451576: Medium severity Crun crun vulnerability
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the crun exec option -u (--user) is incorrectly parsed. The value 1 is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
crunto a version that resolves this vulnerability.Fixed in 1.27
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2451576?
The severity of REDHAT-BUG-2451576 is medium with a CVSS score of 4.
How do I fix REDHAT-BUG-2451576?
To fix REDHAT-BUG-2451576, update to crun version 1.27 or later where the issue is resolved.
What does REDHAT-BUG-2451576 affect?
REDHAT-BUG-2451576 affects crun versions 1.19 through 1.26, specifically the `-u` or `--user` option.
What are the implications of REDHAT-BUG-2451576?
The implications of REDHAT-BUG-2451576 include running processes with elevated privileges unintentionally.
When was REDHAT-BUG-2451576 published?
REDHAT-BUG-2451576 was published on March 26, 2026.