A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then… (CVE-2026-88265)
CVE-2026-88265 is a moderate security flaw in crun affecting versions 1.29.1 and earlier. The vulnerability allows a non-root container process to follow a symlink when reopening /dev/null after pivot_root, potentially attaching a host file to container stdio and changing its ownership. This issue requires specific conditions, including a malicious container image replacing /dev/null with a symlink and the absence of a mounted /dev inside the container. Default configurations that mount a fresh /dev are not vulnerable. No official fix or patch is currently available.
AI Analysis
Technical Summary
CVE-2026-88265 is a moderate severity vulnerability in crun where, after the pivot_root operation, reopening /dev/null for standard input/output can follow a symbolic link. This behavior allows a container process with low privileges to attach a host bind-mounted file to the container's stdio and change the ownership of that file. Exploitation requires a malicious container image that replaces /dev/null with a symlink and the absence of a mounted fresh /dev inside the container. The flaw is classified under CWE-59 (Improper Link Resolution Before File Access). No official fix or patch is currently available for affected versions 1.29.1 and earlier. Default container configurations that mount a fresh /dev are not exposed to this issue.
Potential Impact
An attacker with low privileges inside a container can write to and change ownership of a host bind-mounted file by exploiting the symlink following behavior of /dev/null reopening after pivot_root. This can lead to unauthorized modification of host files from within the container. There is no impact on confidentiality or availability, but the integrity of host files can be compromised. Exploitation requires specific conditions, including a malicious container image and particular container configurations.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Mitigation options are limited and do not meet Red Hat's criteria for ease of use, applicability, or stability. Default container configurations that mount a fresh /dev are not vulnerable. Users should avoid running containers with configurations that do not mount a fresh /dev or allow /dev/null to be replaced by a symlink. Monitor vendor advisories for updates and fixes.
A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then… (CVE-2026-88265)
Description
CVE-2026-88265 is a moderate security flaw in crun affecting versions 1.29.1 and earlier. The vulnerability allows a non-root container process to follow a symlink when reopening /dev/null after pivot_root, potentially attaching a host file to container stdio and changing its ownership. This issue requires specific conditions, including a malicious container image replacing /dev/null with a symlink and the absence of a mounted /dev inside the container. Default configurations that mount a fresh /dev are not vulnerable. No official fix or patch is currently available.
CVSS v3.1
Score 5.6medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-88265 is a moderate severity vulnerability in crun where, after the pivot_root operation, reopening /dev/null for standard input/output can follow a symbolic link. This behavior allows a container process with low privileges to attach a host bind-mounted file to the container's stdio and change the ownership of that file. Exploitation requires a malicious container image that replaces /dev/null with a symlink and the absence of a mounted fresh /dev inside the container. The flaw is classified under CWE-59 (Improper Link Resolution Before File Access). No official fix or patch is currently available for affected versions 1.29.1 and earlier. Default container configurations that mount a fresh /dev are not exposed to this issue.
Potential Impact
An attacker with low privileges inside a container can write to and change ownership of a host bind-mounted file by exploiting the symlink following behavior of /dev/null reopening after pivot_root. This can lead to unauthorized modification of host files from within the container. There is no impact on confidentiality or availability, but the integrity of host files can be compromised. Exploitation requires specific conditions, including a malicious container image and particular container configurations.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Mitigation options are limited and do not meet Red Hat's criteria for ease of use, applicability, or stability. Default container configurations that mount a fresh /dev are not vulnerable. Users should avoid running containers with configurations that do not mount a fresh /dev or allow /dev/null to be replaced by a symlink. Monitor vendor advisories for updates and fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cwhr-hwj2-cjrp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-88265"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6aa2af5facd9273b4925a614
Added to database: 09/10/2026, 13:23:43 UTC
Last enriched: 09/10/2026, 13:27:56 UTC
Last updated: 09/10/2026, 17:00:39 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.