Logo
vulnerabilityCVE-2026-30892
Name
CVE-2026-30892
Source
NVD ( link)Debian ( link)
Description
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
crun
Exploitable

Vulnerability Ratings#


0
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.18.2
Not Affected
openwrt
master
1.28-r1
Not Affected
openwrt
openwrt-25.12
1.17-r3
Not Affected