crun 1.29.1: /dev Console Redirect via Terminal Setup Insecure Bind-Mount
CVE-2026-88264 Published on September 10, 2026
Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.
Vulnerability Analysis
CVE-2026-88264 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-88264 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-88264
Want to know whenever a new CVE is published for Red Hat Hummingbird? stack.watch will email you.