Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/containers/crun

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.

Join the discussion

CVE-2026-88265 is a moderate security flaw in crun affecting versions 1.29.1 and earlier. The vulnerability allows a non-root container process to follow a symlink when reopening /dev/null after pivot_root, potentially attaching a host file to container stdio and changing its ownership. This requires specific conditions, such as a malicious container image replacing /dev/null with a symlink and the container not mounting a fresh /dev. No fixed release is currently available, and default configurations that mount a fresh /dev are not exposed to this issue.

Join the discussion

CVE-2026-84042 is a high-severity vulnerability in crun affecting versions 1.29 and later. When crun is built with libkrun and a container is started rootful with passt networking enabled (krun.use_passt), it can execute attacker-controlled payloads from the container image with host root privileges. This is a regression introduced in crun 1.29. The issue involves improper privilege management, allowing privilege escalation to host root. Mitigation currently involves avoiding running untrusted container images with krun and passt networking until a fixed version is released.

Join the discussion

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/dev`, crun follows that symlink and creates the default device nodes and stdio symlinks at the symlink target outside the container rootfs. In a local rootful crun replay, this created fixed device nodes and symlinks outside the rootfs before crun returned failure. A pre-existing file named `ptmx` in the target directory was also replaced by crun's forced `ptmx -> pts/ptmx` symlink. Version 1.28 fixes the issue.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/containers/crun
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses