* [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892
@ 2026-08-23 10:03 Peter Marko
2026-08-23 10:03 ` [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766 Peter Marko
2026-09-01 14:57 ` [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Bruce Ashfield
0 siblings, 2 replies; 4+ messages in thread
From: Peter Marko @ 2026-08-23 10:03 UTC (permalink / raw)
To: meta-virtualization; +Cc: Peter Marko
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
[1] https://security-tracker.debian.org/tracker/CVE-2026-30892
Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
.../crun/crun/CVE-2026-30892.patch | 53 +++++++++++++++++++
recipes-containers/crun/crun_git.bb | 1 +
2 files changed, 54 insertions(+)
create mode 100644 recipes-containers/crun/crun/CVE-2026-30892.patch
diff --git a/recipes-containers/crun/crun/CVE-2026-30892.patch b/recipes-containers/crun/crun/CVE-2026-30892.patch
new file mode 100644
index 00000000..3d900cc3
--- /dev/null
+++ b/recipes-containers/crun/crun/CVE-2026-30892.patch
@@ -0,0 +1,53 @@
+From 1bd7f42446999b0e76bc3d575392e05c943b0b01 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Erik=20Sj=C3=B6lund?= <erik.sjolund@gmail.com>
+Date: Sat, 7 Mar 2026 19:19:41 +0100
+Subject: [PATCH] exec: fix CVE-2026-30892
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Fix parsing of the -u (--user) option for "crun exec".
+
+Before:
+Value "1" is interpreted as UID=0 GID=0
+
+After:
+Value "1" is interpreted as UID=1 GID=0
+
+Commit 85d4db3d8b27c9ca606eea5f007c58a752ae77aa introduced the
+regression.
+
+Reference:
+https://github.com/containers/crun/security/advisories/GHSA-4vg2-xjqj-7chj
+
+Signed-off-by: Erik Sjölund <erik.sjolund@gmail.com>
+
+CVE: CVE-2026-30892
+Upstream-Status: Backport [https://github.com/containers/crun/commit/1bd7f42446999b0e76bc3d575392e05c943b0b01]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/exec.c | 7 +++----
+ 1 file changed, 3 insertions(+), 4 deletions(-)
+
+diff --git a/src/exec.c b/src/exec.c
+index 36c6084c..5713bbcf 100644
+--- a/src/exec.c
++++ b/src/exec.c
+@@ -214,14 +214,13 @@ make_oci_process_user (const char *userspec)
+ l = strtoll (userspec, &endptr, 10);
+ if (errno == ERANGE)
+ libcrun_fail_with_error (0, "invalid UID specified");
++ if (l < INT_MIN || l > INT_MAX)
++ libcrun_fail_with_error (0, "invalid UID specified");
++ u->uid = (int) l;
+ if (*endptr == '\0')
+ return u;
+ if (*endptr != ':')
+ libcrun_fail_with_error (0, "invalid USERSPEC specified");
+- if (l < INT_MIN || l > INT_MAX)
+- libcrun_fail_with_error (0, "invalid UID specified");
+-
+- u->uid = (int) l;
+
+ errno = 0;
+ l = strtoll (endptr + 1, &endptr, 10);
diff --git a/recipes-containers/crun/crun_git.bb b/recipes-containers/crun/crun_git.bb
index ea14e8ec..e8d87484 100644
--- a/recipes-containers/crun/crun_git.bb
+++ b/recipes-containers/crun/crun_git.bb
@@ -17,6 +17,7 @@ SRC_URI = "git://github.com/containers/crun.git;branch=main;name=crun;protocol=h
git://github.com/containers/yajl.git;branch=main;name=yajl;destsuffix=${BB_GIT_DEFAULT_DESTSUFFIX}/libocispec/yajl;protocol=https \
file://0001-libocispec-correctly-parse-JSON-schema-references.patch;patchdir=libocispec \
file://0002-libocispec-fix-array-items-parsing.patch;patchdir=libocispec \
+ file://CVE-2026-30892.patch \
"
PV = "1.26.0+git"
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766
2026-08-23 10:03 [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Peter Marko
@ 2026-08-23 10:03 ` Peter Marko
2026-09-01 14:57 ` Bruce Ashfield
2026-09-01 14:57 ` [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Bruce Ashfield
1 sibling, 1 reply; 4+ messages in thread
From: Peter Marko @ 2026-08-23 10:03 UTC (permalink / raw)
To: meta-virtualization; +Cc: Peter Marko
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
[1] https://security-tracker.debian.org/tracker/CVE-2026-47766
Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
.../crun/crun/CVE-2026-47766.patch | 161 ++++++++++++++++++
recipes-containers/crun/crun_git.bb | 1 +
2 files changed, 162 insertions(+)
create mode 100644 recipes-containers/crun/crun/CVE-2026-47766.patch
diff --git a/recipes-containers/crun/crun/CVE-2026-47766.patch b/recipes-containers/crun/crun/CVE-2026-47766.patch
new file mode 100644
index 00000000..0a369b46
--- /dev/null
+++ b/recipes-containers/crun/crun/CVE-2026-47766.patch
@@ -0,0 +1,161 @@
+From c6f338ac2e26e216ab7820b91863a0b84e608097 Mon Sep 17 00:00:00 2001
+From: JUNYI LIU <moss80199.cs05@nycu.edu.tw>
+Date: Mon, 25 May 2026 22:45:06 +0800
+Subject: [PATCH] Do not follow rootfs /dev symlinks (CVE-2026-47766)
+
+Open rootfs /dev with safe_openat before creating default devices or handler-specific devices. This keeps rootfs-controlled /dev symlinks from redirecting device setup outside the container rootfs.
+
+Add a regression test covering a rootfs /dev symlink to an outside directory and verify that the outside target is not populated or replaced.
+
+Signed-off-by: JUNYI LIU <moss80199.cs05@nycu.edu.tw>
+
+CVE: CVE-2026-47766
+Upstream-Status: Backport [https://github.com/containers/crun/commit/c6f338ac2e26e216ab7820b91863a0b84e608097]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/libcrun/handlers/krun.c | 4 +-
+ src/libcrun/linux.c | 4 +-
+ tests/test_devices.py | 84 +++++++++++++++++++++++++++++++++++++
+ 3 files changed, 88 insertions(+), 4 deletions(-)
+
+diff --git a/src/libcrun/handlers/krun.c b/src/libcrun/handlers/krun.c
+index 5e1f3e54..6e249a9b 100644
+--- a/src/libcrun/handlers/krun.c
++++ b/src/libcrun/handlers/krun.c
+@@ -609,9 +609,9 @@ libkrun_configure_container (void *cookie, enum handler_configure_phase phase,
+ }
+ }
+
+- devfd = openat (rootfsfd, "dev", O_PATH | O_DIRECTORY | O_CLOEXEC);
++ devfd = safe_openat (rootfsfd, rootfs, "dev", O_PATH | O_DIRECTORY | O_CLOEXEC, 0, err);
+ if (UNLIKELY (devfd < 0))
+- return crun_make_error (err, errno, "open /dev directory in `%s`", rootfs);
++ return devfd;
+
+ ret = check_running_in_user_namespace (err);
+ if (UNLIKELY (ret < 0))
+diff --git a/src/libcrun/linux.c b/src/libcrun/linux.c
+index 24569dec..fcb62dbf 100644
+--- a/src/libcrun/linux.c
++++ b/src/libcrun/linux.c
+@@ -1754,9 +1754,9 @@ create_missing_devs (libcrun_container_t *container, bool binds, libcrun_error_t
+ if (! def || ! def->linux)
+ return 0;
+
+- devfd = openat (get_private_data (container)->rootfsfd, "dev", O_CLOEXEC | O_PATH | O_DIRECTORY);
++ devfd = safe_openat (get_private_data (container)->rootfsfd, rootfs, "dev", O_CLOEXEC | O_PATH | O_DIRECTORY, 0, err);
+ if (UNLIKELY (devfd < 0))
+- return crun_make_error (err, errno, "open `/dev` directory in `%s`", rootfs);
++ return devfd;
+
+ for (i = 0; i < def->linux->devices_len; i++)
+ {
+diff --git a/tests/test_devices.py b/tests/test_devices.py
+index 1a973025..4f0a2bb6 100755
+--- a/tests/test_devices.py
++++ b/tests/test_devices.py
+@@ -18,6 +18,7 @@
+ import os
+ import subprocess
+ import shutil
++import json
+ from tests_utils import *
+
+ def test_mode_device():
+@@ -368,6 +369,88 @@ def test_mknod_char_device():
+ return -1
+ return 0
+
++def test_dev_symlink_does_not_populate_outside_rootfs():
++ if is_rootless():
++ return (77, "requires root privileges")
++
++ workdir = os.path.join(get_tests_root(), "dev-symlink")
++ bundle = os.path.join(workdir, "bundle")
++ rootfs = os.path.join(bundle, "rootfs")
++ outside_dev = os.path.join(workdir, "outside-dev")
++ runtime_root = os.path.join(workdir, "run")
++ shutil.rmtree(workdir, ignore_errors=True)
++ try:
++ os.makedirs(rootfs)
++ os.makedirs(outside_dev)
++ os.makedirs(runtime_root)
++ ptmx_marker = os.path.join(outside_dev, "ptmx")
++ with open(ptmx_marker, "w") as f:
++ f.write("outside marker\n")
++
++ os.symlink(outside_dev, os.path.join(rootfs, "dev"))
++ shutil.copy2(get_init_path(), os.path.join(rootfs, "init"))
++ os.chmod(os.path.join(rootfs, "init"), 0o755)
++
++ conf = {
++ "ociVersion": "1.0.2",
++ "process": {
++ "terminal": False,
++ "user": {"uid": 0, "gid": 0},
++ "args": ["/init", "true"],
++ "env": ["PATH=/bin"],
++ "cwd": "/",
++ },
++ "root": {
++ "path": "rootfs",
++ "readonly": True,
++ },
++ "mounts": [
++ {"destination": "/proc", "type": "proc", "source": "proc"},
++ ],
++ "linux": {
++ "namespaces": [
++ {"type": "mount"},
++ {"type": "pid"},
++ {"type": "ipc"},
++ {"type": "uts"},
++ ],
++ },
++ }
++ with open(os.path.join(bundle, "config.json"), "w") as f:
++ f.write(json.dumps(conf))
++
++ container_id = "test-dev-symlink"
++ crun = get_crun_path()
++
++ try:
++ subprocess.check_output([crun, "--root", runtime_root, "run", "-b", bundle, container_id],
++ stderr=subprocess.STDOUT)
++ logger.info("container unexpectedly started with rootfs /dev symlink")
++ return -1
++ except subprocess.CalledProcessError:
++ pass
++ finally:
++ subprocess.run([crun, "--root", runtime_root, "delete", "-f", container_id],
++ stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
++
++ outside_entries = sorted(os.listdir(outside_dev))
++ if outside_entries != ["ptmx"]:
++ logger.info("rootfs /dev symlink target was populated outside rootfs: %s", outside_entries)
++ return -1
++
++ if os.path.islink(ptmx_marker):
++ logger.info("rootfs /dev symlink target ptmx marker was replaced with a symlink")
++ return -1
++
++ with open(ptmx_marker) as f:
++ if f.read() != "outside marker\n":
++ logger.info("rootfs /dev symlink target ptmx marker content changed")
++ return -1
++
++ return 0
++ finally:
++ shutil.rmtree(workdir, ignore_errors=True)
++
+ def test_allow_device_read_only():
+ if is_rootless():
+ return (77, "requires root privileges")
+@@ -425,6 +508,7 @@ def test_allow_device_read_only():
+ all_tests = {
+ "mknod-fifo-device": test_mknod_fifo_device,
+ "mknod-char-device": test_mknod_char_device,
++ "dev-symlink-does-not-populate-outside-rootfs": test_dev_symlink_does_not_populate_outside_rootfs,
+ "allow-device-read-only": test_allow_device_read_only,
+ "owner-device" : test_owner_device,
+ "deny-devices" : test_deny_devices,
diff --git a/recipes-containers/crun/crun_git.bb b/recipes-containers/crun/crun_git.bb
index e8d87484..809b6c01 100644
--- a/recipes-containers/crun/crun_git.bb
+++ b/recipes-containers/crun/crun_git.bb
@@ -18,6 +18,7 @@ SRC_URI = "git://github.com/containers/crun.git;branch=main;name=crun;protocol=h
file://0001-libocispec-correctly-parse-JSON-schema-references.patch;patchdir=libocispec \
file://0002-libocispec-fix-array-items-parsing.patch;patchdir=libocispec \
file://CVE-2026-30892.patch \
+ file://CVE-2026-47766.patch \
"
PV = "1.26.0+git"
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892
2026-08-23 10:03 [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Peter Marko
2026-08-23 10:03 ` [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766 Peter Marko
@ 2026-09-01 14:57 ` Bruce Ashfield
1 sibling, 0 replies; 4+ messages in thread
From: Bruce Ashfield @ 2026-09-01 14:57 UTC (permalink / raw)
To: peter.marko; +Cc: meta-virtualization
merged
Bruce
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766
2026-08-23 10:03 ` [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766 Peter Marko
@ 2026-09-01 14:57 ` Bruce Ashfield
0 siblings, 0 replies; 4+ messages in thread
From: Bruce Ashfield @ 2026-09-01 14:57 UTC (permalink / raw)
To: peter.marko; +Cc: meta-virtualization
merged
Bruce
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-01 14:58 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-23 10:03 [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Peter Marko
2026-08-23 10:03 ` [meta-virtualization][wrynose][PATCH 2/2] crun: patch CVE-2026-47766 Peter Marko
2026-09-01 14:57 ` Bruce Ashfield
2026-09-01 14:57 ` [meta-virtualization][wrynose][PATCH 1/2] crun: patch CVE-2026-30892 Bruce Ashfield
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.