CyberRota Analysis
AI-GeneratedA vulnerability in crun allows an attacker to execute malicious payloads with host root privileges when crun is built with libkrun and a container is started in a rootful mode with passt networking enabled. This flaw, introduced in version 1.29, poses a significant risk to systems using affected versions of crun, especially those running untrusted container images. Organizations utilizing crun for container management should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29