Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95985.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-95985
Upstream
Published
2026-08-14T17:18:18Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-47766 affecting package crun 1.24-5
Details

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs /dev directory without O_NOFOLLOW. If an OCI bundle contains rootfs/dev as a symlink and the bundle configuration does not mount /dev, crun follows that symlink and creates the default device nodes and stdio symlinks at the symlink target outside the container rootfs. In a local rootful crun replay, this created fixed device nodes and symlinks outside the rootfs before crun returned failure. A pre-existing file named ptmx in the target directory was also replaced by crun's forced ptmx -> pts/ptmx symlink. Version 1.28 fixes the issue.

References

Affected packages

Azure Linux:3 / crun

Package

Name
crun
Purl
pkg:rpm/azure-linux/crun

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.24-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95985.json"