CVE-2026-30892
published 2026-03-26CVE-2026-30892: crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.5th percentile
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| containers | crun | — | — |
| crun_project | crun | >= 0 < 1.27-1 | 1.27-1 |
| crun_project | crun | >= 1.19 < 1.27 | 1.27 |
| debian | crun | < crun 1.27-1 (forky) | crun 1.27-1 (forky) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8NONE
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-30892: crun is an open source OCI Container Runtime fully written in C
osv·2026-03-26·CVSS 7.8
CVE-2026-30892 [HIGH] CVE-2026-30892: crun is an open source OCI Container Runtime fully written in C
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
Red Hat
crun: crun: Privilege escalation due to incorrect parsing of the `--user` option
vendor_redhat·2026-03-25·CVSS 7.8
CVE-2026-30892 [NONE] CWE-115 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option
crun: crun: Privilege escalation due to incorrect parsing of the `--user` option
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
A flaw was found in crun, an open-source OCI Container Runtime. A local user can exploit this vulnerability due to incorrect parsing of the `--user` option when using `crun exec`. The value `1` is misinterpreted as root privileges (User ID 0 and Group ID 0) instead of the intended User ID 1 and Group ID 0. This allows a process to run with higher privileges than expected, le
Debian
CVE-2026-30892: crun - crun is an open source OCI Container Runtime fully written in C. In versions 1.1...
vendor_debian·2026·CVSS 7.8
CVE-2026-30892 [NONE] CVE-2026-30892: crun - crun is an open source OCI Container Runtime fully written in C. In versions 1.1...
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.27-1)
sid: resolved (fixed in 1.27-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option [fedora-42]
bugzilla·2026-03-27·CVSS 7.8
CVE-2026-30892 [NONE] CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option [fedora-42]
CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-32cf2c53f7 (crun-1.27-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-32cf2c53f7
---
FEDORA-2026-32cf2c53f7 (crun-1.27-1.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.
Bugzilla
CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option
bugzilla·2026-03-26·CVSS 7.8
CVE-2026-30892 [NONE] CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option
CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option
crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:6622 https://access.redhat.com/errata/RHSA-2026:6622
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6621 https://access.redhat.com/errata/RHSA-2026:6621
Wiz
CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32776 [MEDIUM] CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32776 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat-devel
firefox-debugsource
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 20, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity
Wiz
CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-25210 [MEDIUM] CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25210 :
Alma Linux vulnerability analysis and mitigation
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Source : NVD
## 7.8
Score
Published January 30, 2026
Severity HIGH
CNA Score 6.9
Affected Technologies
Alma Linux
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libxmltok
libexpat1
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Severity HIGH Has Fix Added at: Feb 04, 2026
Alpine edge Severity HIGH Has Fix Added at: Feb 03, 2026
CBL-Mariner 2.0 Severity MEDIUM
Wiz
CVE-2026-24515 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-24515 [LOW] CVE-2026-24515 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24515 :
Alma Linux vulnerability analysis and mitigation
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
Source : NVD
## 2.5
Score
Published January 23, 2026
Severity LOW
CNA Score 2.9
Affected Technologies
Alma Linux
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
mingw-expat
libexpat1-32bit
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Severity LOW Has Fix Added at: Feb 04, 2026
Alpine edge Severity LOW Has Fix Added at: Feb 03, 2026
CBL-Mariner 2.0 Severity LOW Has Fix Added at: Feb 08, 2026
CBL-Mariner 3.0 Severity LOW Has
Wiz
CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-32778 [LOW] CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32778 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 2.9
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
thunderbird
libexpat-devel
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar
Wiz
CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32777 [MEDIUM] CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32777 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat1
seal-expat
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity MEDIUM Has Fix Added at: Mar 17, 2026
Red
Wiz
CVE-2026-4177 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-4177 [MEDIUM] CVE-2026-4177 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4177 :
Alma Linux vulnerability analysis and mitigation
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.
The heap overflow occurs when class names exceed the initial 512-byte allocation.
The base64 decoder could read past the buffer end on trailing newlines.
strtok mutated n->type_id in place, corrupting shared node data.
A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
Source : NVD
## 9.1
Score
Published March 16, 2026
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Dat
Wiz
CVE-2026-30892 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-30892 [MEDIUM] CVE-2026-30892 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30892 :
NixOS vulnerability analysis and mitigation
crun exec
-u
--user
1
Source : NVD
## 7.8
Score
Published March 26, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
NixOS
Alma Linux
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
crun-krun
crun-wasm
Sources
NVD
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Apr 06, 2026
Alpine 3.23 Severity HIGH Has Fix Added at: Mar 29, 2026
Alpine edge Severity HIGH Has Fix Added at: Mar 26, 2026
Debian 13 Severity MEDIUM No Fix Added at: Mar 29, 2026
Debian 14 Severity HIGH Has Fix Added at: Mar 29, 2026
Homebrew Severity HIGH Has Fix Added at
2026-03-26
Published