PatchSiren cyber security CVE debrief
CVE-2026-84042 Red Hat CVE debrief
A flaw in crun allows execution of attacker-controlled payloads with host root privileges when built with libkrun and used with passt networking in rootful containers. This issue is a regression in crun 1.29, affecting versions >= 1.29. The vulnerability is a result of crun's interaction with libkrun and passt networking, which enables the execution of attacker-controlled payloads from the container image with host root privileges. Defenders managing container environments using crun, especially those using rootful containers with libkrun and passt networking, should assess their exposure and verify the versions of crun in use. This requires reviewing container configurations, crun
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-15
Who should care
Defenders managing container environments using crun, especially those using rootful containers with libkrun and passt networking, should assess their exposure and verify the versions of crun in use.
Why it matters
CVE-2026-84042 is a high-severity vulnerability in crun that allows execution of attacker-controlled payloads with root privileges in specific configurations. Defenders should prioritize verifying exposure, especially in rootful container environments using crun with libkrun and passt networking.
- Potential for root privilege escalation in container environments
- Need for verification of crun versions and configurations
- Possible impact on container security posture
Technical summary
The vulnerability occurs when crun is built with libkrun and used to start a container rootful with passt networking. This configuration allows crun to execute attacker-controlled payloads from the container image with host root privileges. The issue is a regression introduced in crun version 1.29, affecting all versions from 1.29 onwards. The vulnerability is a result of the interaction between crun, libkrun, and passt networking, which enables the execution of attacker-controlled payloads. Defenders should prioritize verifying exposure in rootful container environments using crun with libkrun and passt networking, and assess the need for updates or compensating controls. The technical details are based on the
Defensive priority
Defenders should prioritize verifying exposure in rootful container environments using crun with libkrun and passt networking, and assess the need for updates or compensating controls.
Recommended defensive actions
- Verify crun versions in use and assess exposure in rootful container environments
- Check if libkrun and passt networking are used with crun
- Review container configurations for potential vulnerabilities
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Red Hat has a reference page for this CVE. The crun GitHub repository is also referenced. The vulnerability is confirmed in crun version 1.29 and later. Defenders should verify their exposure by checking the versions of crun in use, especially in rootful container environments with libkrun and passt networking. The evidence is limited to public sources and may not be comprehensive. Further verification is recommended to ensure accurate assessment of exposure and impact
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84042 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84042
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84042 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84042
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-84042
-
Source reference
Unverified legacy reference
URL: https://github.com/containers/crun/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.