{"id":"AZL-95985","summary":"CVE-2026-47766 affecting package crun 1.24-5","details":"crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/dev`, crun follows that symlink and creates the default device nodes and stdio symlinks at the symlink target outside the container rootfs. In a local rootful crun replay, this created fixed device nodes and symlinks outside the rootfs before crun returned failure. A pre-existing file named `ptmx` in the target directory was also replaced by crun's forced `ptmx -\u003e pts/ptmx` symlink. Version 1.28 fixes the issue.","modified":"2026-08-31T05:26:07Z","published":"2026-08-14T17:18:18Z","upstream":["CVE-2026-47766"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47766"}],"affected":[{"package":{"name":"crun","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/crun"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.24-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95985.json"}}],"schema_version":"1.9.0"}