CVE-2026-84042

HIGH CVSS 3.1: 7.8 EPSS 0.10%
Updated Sep 10, 2026
Payload
Parameter Value
CVSS 7.8 (HIGH)
Type CWE-269 (Improper Privilege Management)
Vendor Payload
Public PoC No

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29.

It affects crun >= 1.29

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

red hat:red hat hardened images