CVE-2026-88265
Awaiting Analysis Awaiting Analysis - Queue

crun Symlink Following in Container stdio

Vulnerability report for CVE-2026-88265, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-15

Assigner: redhat-SADP

Description

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-15
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the crun container runtime affecting versions 1.29.1 and earlier. It involves a non-root container process exploiting a symlink following issue after pivot_root to reopen /dev/null for stdio and attach a host file to the container's stdio. This can allow changing the file's ownership on the host system.

Detection Guidance

Detection requires checking if crun versions 1.29.1 or earlier are installed and verifying if containers are running with non-default /dev configurations. Inspect container images for malicious /dev/null replacements and monitor for unexpected file ownership changes on the host. No specific commands are provided in the resources.

Impact Analysis

An attacker could modify files or bypass security mechanisms on the host system by changing file ownership. Exploitation requires specific conditions like a malicious container image replacing /dev/null with a symlink while /dev is not mounted within the container.

Compliance Impact

This vulnerability primarily impacts integrity by allowing non-root container processes to modify host files via symlink exploitation. For GDPR, it could lead to unauthorized data alteration if sensitive files are affected. HIPAA compliance may be impacted if protected health information files are modified or accessed improperly. The flaw enables integrity compromise, which is a key concern for both regulations.

Mitigation Strategies

Mitigation options are unavailable or do not meet stability criteria per Red Hat. Avoid running untrusted containers and ensure /dev is mounted fresh in containers. Monitor for file ownership changes and restrict container privileges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88265. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart