{"id":"AZL-80951","summary":"CVE-2026-30892 affecting package crun 1.24-5","details":"crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the  `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and  GID 0. The process thus runs with higher privileges than expected. Version 1.27 patches the issue.","modified":"2026-08-30T05:24:52Z","published":"2026-03-26T00:16:38Z","upstream":["CVE-2026-30892"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30892"}],"affected":[{"package":{"name":"crun","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/crun"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.24-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80951.json"}}],"schema_version":"1.9.0"}