{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acrun_projectcrun/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:crun_project:crun:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-84042"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["crun (\u003e= 1.29)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","container-security","linux"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-84042 affects the crun container runtime when compiled with libkrun support. The issue arises when a container is executed with root privileges and configured to use passt networking via the 'krun.use_passt' setting. Under these specific conditions, a regression introduced in version 1.29 allows an attacker to manipulate the container execution environment. Specifically, the runtime may inadvertently execute malicious payloads defined within the container image with the effective privileges of the host root user. This represents a critical breakdown in container isolation, as an attacker with control over the container image or runtime configuration can achieve full system compromise. The vulnerability affects all versions of crun starting from 1.29. Defenders should audit container runtime configurations to identify systems utilizing libkrun and passt networking simultaneously.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious container image containing a payload designed to execute upon container startup.\u003c/li\u003e\n\u003cli\u003eAttacker gains access to a host system where the container runtime is configured to use crun \u0026gt;= 1.29.\u003c/li\u003e\n\u003cli\u003eAttacker ensures the container runtime is built with libkrun and configured with passt networking (krun.use_passt).\u003c/li\u003e\n\u003cli\u003eAttacker triggers the deployment of the malicious container image using rootful execution.\u003c/li\u003e\n\u003cli\u003eThe crun runtime initializes the container using libkrun and passt networking.\u003c/li\u003e\n\u003cli\u003eDue to the vulnerability, the runtime executes the payload within the image context.\u003c/li\u003e\n\u003cli\u003eThe payload executes with host root privileges, bypassing intended container isolation.\u003c/li\u003e\n\u003cli\u003eAttacker gains full control over the host system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged actor to escalate privileges to root on the host machine. This affects any infrastructure relying on crun as its container runtime, specifically those utilizing libkrun-based sandboxing. Impact includes full system compromise, exfiltration of sensitive host-level data, and potential persistence mechanisms being established within the host environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade crun to a version where this regression is patched once available from your distribution vendor.\u003c/li\u003e\n\u003cli\u003eUntil a patch is applied, disable the use of libkrun or passt networking (krun.use_passt) for rootful containers.\u003c/li\u003e\n\u003cli\u003eAudit container orchestration configurations (e.g., Kubernetes, Podman, or Docker) to identify environments running crun 1.29 or later.\u003c/li\u003e\n\u003cli\u003eImplement restricted container security policies to prevent the deployment of untrusted container images.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-10T11:06:05Z","date_published":"2026-09-10T11:06:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-crun-priv-esc/","summary":"A privilege escalation vulnerability in crun versions 1.29 and later allows attackers to execute container-image payloads with host root privileges when using libkrun with passt networking.","title":"Privilege Escalation in crun via libkrun and passt Networking","url":"https://feed.craftedsignal.io/briefs/2026-09-crun-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:crun_project:crun:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}