Junglewise Threat Intelligence

CVE-2026-84042: crun privilege escalation in libkrun with passt networking

CVE-2026-84042 · Severity: high · CVSS 7.8 · Published 2026-09-10

Technologies: Containers Crun. Vendors: Containers.

Executive brief

crun is a container runtime that can execute containers on Linux systems. When built with libkrun support and configured to use passt networking, a vulnerability allows an attacker to execute malicious code from a container image with root privileges on the host system, bypassing normal container isolation. This affects rootful (root-privileged) containers and can lead to complete host compromise.

Technical details

The vulnerability is an improper privilege management flaw (CWE-269) that occurs when crun is built with libkrun and a container is started in rootful mode with passt networking enabled (krun.use_passt). An attacker who controls the container image can execute arbitrary payloads with host root privileges, escaping normal container isolation boundaries. The attack requires low privileges and no user interaction but has high complexity requirements due to the specific build and runtime configuration needed. The issue is a regression introduced in crun 1.29 and affects all versions >= 1.29. Mitigation is to avoid running untrusted images with krun and passt networking until a patch is released.

Affected products

  • containers crun >= 1.29

Timeline

  • 2026-09-10: disclosed

References

Related threats