PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84042 Red Hat CVE debrief

A flaw in crun allows execution of attacker-controlled payloads with host root privileges when built with libkrun and used with passt networking in rootful containers. This issue is a regression in crun 1.29, affecting versions >= 1.29. The vulnerability is a result of crun's interaction with libkrun and passt networking, which enables the execution of attacker-controlled payloads from the container image with host root privileges. Defenders managing container environments using crun, especially those using rootful containers with libkrun and passt networking, should assess their exposure and verify the versions of crun in use. This requires reviewing container configurations, crun

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-15
Advisory published
2026-09-10
Advisory updated
2026-09-15

Who should care

Defenders managing container environments using crun, especially those using rootful containers with libkrun and passt networking, should assess their exposure and verify the versions of crun in use.

Why it matters

CVE-2026-84042 is a high-severity vulnerability in crun that allows execution of attacker-controlled payloads with root privileges in specific configurations. Defenders should prioritize verifying exposure, especially in rootful container environments using crun with libkrun and passt networking.

  • Potential for root privilege escalation in container environments
  • Need for verification of crun versions and configurations
  • Possible impact on container security posture

Technical summary

The vulnerability occurs when crun is built with libkrun and used to start a container rootful with passt networking. This configuration allows crun to execute attacker-controlled payloads from the container image with host root privileges. The issue is a regression introduced in crun version 1.29, affecting all versions from 1.29 onwards. The vulnerability is a result of the interaction between crun, libkrun, and passt networking, which enables the execution of attacker-controlled payloads. Defenders should prioritize verifying exposure in rootful container environments using crun with libkrun and passt networking, and assess the need for updates or compensating controls. The technical details are based on the

Defensive priority

Defenders should prioritize verifying exposure in rootful container environments using crun with libkrun and passt networking, and assess the need for updates or compensating controls.

Recommended defensive actions

  • Verify crun versions in use and assess exposure in rootful container environments
  • Check if libkrun and passt networking are used with crun
  • Review container configurations for potential vulnerabilities
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Red Hat has a reference page for this CVE. The crun GitHub repository is also referenced. The vulnerability is confirmed in crun version 1.29 and later. Defenders should verify their exposure by checking the versions of crun in use, especially in rootful container environments with libkrun and passt networking. The evidence is limited to public sources and may not be comprehensive. Further verification is recommended to ensure accurate assessment of exposure and impact

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84042 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84042

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84042 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84042

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.