Impact
A regression in crun 1.29 allows an attacker to run code from a container image with host root privileges when the runtime is built with libkrun and a rootful container is started with passt networking. This flaw is a CWE-269 weakness that can compromise the entire host system if an attacker supplies a malicious image. The vulnerability requires the specific configuration of rootful krun with passt networking, but once those prerequisites are met, arbitrary payload execution as root is possible.
Affected Systems
Red Hat Hardened Images, which include the crun container runtime built with libkrun. The flaw affects crun versions 1.29 and later. Users that employ rootful containers with passt networking in this environment are exposed, while non‑rootful or non‑passt configurations are not directly impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk. EPSS data is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, but the lack of public exploit evidence does not reduce the importance of remediation. An attacker with the ability to supply or modify a container image could exploit the vulnerability by launching a rootful container with passt networking, thereby executing privileged code on the host. The attack vector is inferred to be via the container image; direct exploitation requires these configuration conditions.
OpenCVE Enrichment