REDHAT-BUG-2531222: High severity crun vulnerability
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.usepasst), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun 1.29 and 1.29.1. A patch is available upstream; no fixed release is published yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The affected configuration requires crun built with libkrun, a rootful container, and passt networking enabled through krun.use_passt. The affected crun versions are 1.29 and 1.29.1.
What does an attacker need to exploit the flaw?
An attacker needs control of payload content in a container image that is started in the affected configuration. crun can then execute that attacker-controlled payload with host root privileges.
Is a fix available?
A patch is available upstream, but no fixed crun release has been published yet.