Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for crun Announcement ID: SUSE-SU-2026:22395-1 Release Date: 2026-06-24T08:59:37Z Rating: moderate References: * bsc#1268302 Cross-References: * CVE-2026-47766 CVSS scores: * CVE-2026-47766 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issue * CVE-2026-47766: crun follows rootfs /dev symlink while creating default devices (bsc#1268302). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-766=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * crun-debuginfo-1.14-3.1 * crun-1.14-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47766.html * https://bugzilla.suse.com/show_bug.cgi?id=1268302 . This security update addresses one moderate issue in crun related to symlink handling, applicable for SUSE Micro.. SUSE Linux Micro, crun security, moderate update. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for crun Announcement ID: SUSE-SU-2026:22247-1 Release Date: 2026-06-22T07:17:05Z Rating: moderate References: * bsc#1268302 Cross-References: * CVE-2026-47766 CVSS scores: * CVE-2026-47766 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issue * CVE-2026-47766: crun follows rootfs /dev symlink while creating default devices (bsc#1268302). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-585=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64) * crun-debuginfo-1.15-slfo.1.1_2.1 * crun-1.15-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47766.html * https://bugzilla.suse.com/show_bug.cgi?id=1268302 . Crun security fix addresses a moderate issue in SUSE Linux Micro 6.1, improving system access management and stability.. SUSE Linux Micro, Crun Update, System Access, Security Fix, SUSE Advisory. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # crun-1.27-1.1 on GA media Announcement ID: openSUSE-SU-2026:10524-1 Rating: moderate Cross-References: * CVE-2026-30892 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the crun-1.27-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * crun 1.27-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-30892.html . Explore security advisory for openSUSE Tumbleweed updating crun-1.27-1.1 to address a moderate security issue.. openSUSE, crun, software update, moderate security. . LinuxSecurity.com Team
Automatic update for crun-1.27-1.fc42. Changelog for crun * Wed Mar 25 2026 Packit - 1.27-1 - Update to 1.27 upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-32cf2c53f7 2026-04-10 01:10:26.730864+00:00 -------------------------------------------------------------------------------- Name : crun Product : Fedora 42 Version : 1.27 Release : 1.fc42 URL : https://github.com/containers/crun Summary : OCI runtime written in C Description : crun is a OCI runtime -------------------------------------------------------------------------------- Update Information: Automatic update for crun-1.27-1.fc42. Changelog for crun * Wed Mar 25 2026 Packit - 1.27-1 - Update to 1.27 upstream release -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Packit - 1.27-1 - Update to 1.27 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452162 - CVE-2026-30892 crun: crun: Privilege escalation due to incorrect parsing of the `--user` option [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452162 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-32cf2c53f7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6622", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["crun-debugsource-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.s390x.rpm", "crun-debuginfo-0:1.27-1.el10_1.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.ppc64le.rpm", "crun-debugsource-0:1.27-1.el10_1.x86_64.rpm", "crun-0:1.27-1.el10_1.aarch64.rpm", "crun-debugsource-0:1.27-1.el10_1.aarch64.rpm", "crun-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.x86_64.rpm", "crun-debuginfo-0:1.27-1.el10_1.s390x.rpm", "crun-0:1.27-1.el10_1.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update for crun on Rocky Linux 10 addresses a moderate privilege escalation issue, detailing a security fix and implications.. RockyLinux crun security moderation CVE-2026-30892 privilege escalation. . LinuxSecurity.com Team
Moderate: crun security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6621", "synopsis": "Moderate: crun security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for crun.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "crun is a OCI runtime\n\nSecurity Fix(es):\n\n* crun: crun: Privilege escalation due to incorrect parsing of the `--user` option (CVE-2026-30892)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2451576", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451576", "description": ""}], "cves": [{"name": "CVE-2026-30892", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-30892", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-115"}], "references": [], "publishedAt": "2026-04-08T06:01:52.863918Z", "rpms": {"Rocky Linux 9": {"nvras": ["crun-0:1.27-1.el9_7.aarch64.rpm", "crun-0:1.27-1.el9_7.ppc64le.rpm", "crun-0:1.27-1.el9_7.s390x.rpm", "crun-0:1.27-1.el9_7.src.rpm", "crun-0:1.27-1.el9_7.x86_64.rpm", "crun-debuginfo-0:1.27-1.el9_7.aarch64.rpm", "crun-debuginfo-0:1.27-1.el9_7.ppc64le.rpm", "crun-debuginfo-0:1.27-1.el9_7.s390x.rpm", "crun-debuginfo-0:1.27-1.el9_7.x86_64.rpm", "crun-debugsource-0:1.27-1.el9_7.aarch64.rpm", "crun-debugsource-0:1.27-1.el9_7.ppc64le.rpm", "crun-debugsource-0:1.27-1.el9_7.s390x.rpm", "crun-debugsource-0:1.27-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux crun security update addresses moderate privilege escalation risk with CVE-2026-30892. Immediate action recommended.. crun update moderatevulnerability privilege escalation security advisory. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for crun Announcement ID: SUSE-SU-2026:20452-1 Release Date: 2026-02-17T08:53:07Z Rating: important References: * bsc#1237421 Cross-References: * CVE-2025-24965 CVSS scores: * CVE-2025-24965 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2025-24965 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2025-24965 ( NVD ): 8.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issues: * CVE-2025-24965: .krun_config.json symlink attack creates or overwrites file on the host (bsc#1237421). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-588=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * crun-1.14-2.1 * crun-debuginfo-1.14-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24965.html * https://bugzilla.suse.com/show_bug.cgi?id=1237421 . Critical SUSE update for crun fixes symlink attack vulnerability, ensuring essential patch management.. SUSE Security, crun Update, Symlink Protection, Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
Security fix for GHSA-f42g-r5jj-qh4j. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-166f075581 2025-02-26 01:41:52.376499+00:00 -------------------------------------------------------------------------------- Name : crun Product : Fedora 40 Version : 1.20 Release : 2.fc40 URL : https://github.com/containers/crun Summary : OCI runtime written in C Description : crun is a OCI runtime -------------------------------------------------------------------------------- Update Information: Security fix for GHSA-f42g-r5jj-qh4j -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 10 2025 Lokesh Mandvekar - 1.20-2 - fix gating config * Wed Feb 5 2025 Packit - 1.20-1 - Update to 1.20 upstream release * Tue Dec 31 2024 Lokesh Mandvekar - 1.19.1-2 - TMT: sync tests from upstream -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-166f075581' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.