Security: containers/crun
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
crun follows rootfs /dev symlink while creating default devicesGHSA-7vwr-4279-7gq5 published
May 27, 2026 by giuseppeLow -
Incorrectly parsed `crun exec` option `-u` leads to privilege escalationGHSA-4vg2-xjqj-7chj published
Mar 25, 2026 by giuseppeLow -
.krun_config.json symlink attack creates or overwrites file on the hostGHSA-f42g-r5jj-qh4j published
Feb 19, 2025 by giuseppeHigh -
Default inheritable capabilities for linux container should be emptyGHSA-wr4f-w546-m398 published
Mar 26, 2022 by giuseppeLow -
container breakout with crun < 0.10.5GHSA-w969-8gp4-95wr published
Nov 14, 2019 by giuseppeHigh