An update that solves one vulnerability can now be installed.. # crun-1.27-1.1 on GA media Announcement ID: openSUSE-SU-2026:10524-1 Rating: moderate Cross-References: * CVE-2026-30892 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the crun-1.27-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * crun 1.27-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-30892.html . Explore security advisory for openSUSE Tumbleweed updating crun-1.27-1.1 to address a moderate security issue.. openSUSE, crun, software update, moderate security. . LinuxSecurity.com Team
Automatic update for crun-1.27-1.fc42. Changelog for crun * Wed Mar 25 2026 Packit - 1.27-1 - Update to 1.27 upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-32cf2c53f7 2026-04-10 01:10:26.730864+00:00 -------------------------------------------------------------------------------- Name : crun Product : Fedora 42 Version : 1.27 Release : 1.fc42 URL : https://github.com/containers/crun Summary : OCI runtime written in C Description : crun is a OCI runtime -------------------------------------------------------------------------------- Update Information: Automatic update for crun-1.27-1.fc42. Changelog for crun * Wed Mar 25 2026 Packit - 1.27-1 - Update to 1.27 upstream release -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Packit - 1.27-1 - Update to 1.27 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452162 - CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452162 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-32cf2c53f7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6622", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["crun-debugsource-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.s390x.rpm", "crun-debuginfo-0:1.27-1.el10_1.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.x86_64.rpm", "crun-0:1.27-1.el10_1.aarch64.rpm", "crun-debugsource-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate security update for crun on Rocky Linux 10 addresses privilege escalation risks. Apply the update immediately.. Rocky Linux10, crun update, security patch, privilege escalation, OCI runtime. . LinuxSecurity.com Team
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6622", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["crun-debugsource-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.s390x.rpm", "crun-debuginfo-0:1.27-1.el10_1.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.x86_64.rpm", "crun-0:1.27-1.el10_1.aarch64.rpm", "crun-debugsource-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update for crun on Rocky Linux 10 addresses a moderate privilege escalation issue, detailing a security fix and implications.. RockyLinux crun security moderation CVE-2026-30892 privilege escalation. . LinuxSecurity.com Team
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6622", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["crun-debugsource-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.s390x.rpm", "crun-debuginfo-0:1.27-1.el10_1.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.x86_64.rpm", "crun-0:1.27-1.el10_1.aarch64.rpm", "crun-debugsource-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate security update for crun addresses privilege escalation issue in Rocky Linux 10. Patch details included.. RockyLinux crun security moderate update. . LinuxSecurity.com Team
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6622", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["crun-debugsource-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.s390x.rpm", "crun-debuginfo-0:1.27-1.el10_1.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.x86_64.rpm", "crun-0:1.27-1.el10_1.aarch64.rpm", "crun-debugsource-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Crun security update for Rocky Linux addresses privilege escalation, enhancing system safety.. Rocky Linux Crun SecurityPrivilege Escalation Update. . LinuxSecurity.com Team
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6622", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["crun-debugsource-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.s390x.rpm", "crun-debuginfo-0:1.27-1.el10_1.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.x86_64.rpm", "crun-0:1.27-1.el10_1.aarch64.rpm", "crun-debugsource-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Crun security update available for Rocky Linux 10 to fix moderate privilege escalation issues. Update to enhance system security.. RockyLinux crun security update, moderate security threats, OCI runtime vulnerabilities. . LinuxSecurity.com Team
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6622", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["crun-debugsource-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.s390x.rpm", "crun-debuginfo-0:1.27-1.el10_1.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.x86_64.rpm", "crun-0:1.27-1.el10_1.aarch64.rpm", "crun-debugsource-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Learn about the moderate security update for crun in Rocky Linux addressing a privilege escalation issue.. Rocky Linux crun updatemoderate security fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.