CVE-2019-18837

HIGH

crun < 0.10.5 - Improper Link Resolution Before File Access

Title source: llm
STIX 2.1

Description

An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.

Scores

CVSS v3 8.6
EPSS 0.0142
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-59
Status published
Products (3)
crun_project/crun < 0.10.5
fedoraproject/fedora 30
fedoraproject/fedora 31
Published Nov 13, 2019
Tracked Since Feb 18, 2026