Known vulnerabilities in crun (Red Hat package)
Vendor:
Red Hat Inc.
Software:
crun (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:crun_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
76
Public exploits:
5
Known exploited (KEV):
1
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
1.27-1.el9_6
1.14.3-1.el9_0
1.27-1.el10_1
1.27-1.el9_7
1.20-4.rhaos4.18.el8
1.20-2.rhaos4.18.el9
1.17-2.rhaos4.15.el8
1.17-2.rhaos4.15.el9
1.17-2.rhaos4.16.el8
1.17-2.rhaos4.16.el9
1.17-2.rhaos4.14.el8
1.17-2.rhaos4.14.el9
1.19.1-1.rhaos4.17.el8
1.17-1.rhaos4.17.el8
1.17-1.rhaos4.17.el9
1.14.3-2.rhaos4.17.el8
1.14.3-2.rhaos4.17.el9
1.17-1.rhaos4.14.el8
1.17-1.rhaos4.14.el9
1.17-1.rhaos4.16.el8
1.17-1.rhaos4.16.el9
1.14.3-1.rhaos4.16.el8
1.14.3-1.rhaos4.16.el9
1.14-1.rhaos4.15.el9
1.14-1.rhaos4.13.el8
1.14-1.rhaos4.13.el9
1.14-1.rhaos4.14.el8
1.14-1.rhaos4.14.el9
1.9.2-1.rhaos4.14.el8
1.9.2-1.rhaos4.14.el9
1.9.2-1.rhaos4.13.el8
1.9.2-1.rhaos4.13.el9
1.8.4-1.rhaos4.13.el9
1.4.2-2.rhaos4.12.el8
1.4.2-3.rhaos4.12.el9
1.4.2-2.rhaos4.12.el9
1.4.2-1.rhaos4.11.el8
1.4.2-1.rhaos4.10.el8
Vulnerabilities (76)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128071 - Improper input validation CVE-2026-30892 |
CWE-20 | Low | 1.27-1.el9_6, 1.27-1.el9_7, 1.27-1.el10_1 | 27.04.2026 |
SB2026042773 SB2026042774 SB2026042777 and 2 more |
||
| #VU121565 - Resource exhaustion CVE-2025-65637 |
CWE-400 | Medium | 1.14.3-1.el9_0 | 15.01.2026 |
SB2026011525 SB20260116132 SB2026011920 and 35 more |
||
| #VU118717 - Improper input validation CVE-2025-47913 |
CWE-20 | Low | 1.14.3-1.el9_0 | 24.11.2025 |
SB2025112448 SB2025112455 SB2025112456 and 53 more |
||
| #VU118190 - Resource exhaustion CVE-2025-58183 |
CWE-400 | Medium | 1.14.3-1.el9_0 | 07.11.2025 |
SB2025110705 SB2025110725 SB2025110726 and 177 more |
||
| #VU118106 - UNIX Symbolic Link (Symlink) Following CVE-2025-52565 |
CWE-61 | Low | 1.14.3-1.el9_0 | 05.11.2025 |
SB2025110519 SB2025110530 SB2025110545 and 38 more |
||
| #VU118105 - UNIX Symbolic Link (Symlink) Following CVE-2025-52881 |
CWE-61 | Low | 1.14.3-1.el9_0 | 05.11.2025 |
SB2025110519 SB2025110530 SB2025110545 and 62 more |
||
| #VU118104 - UNIX Symbolic Link (Symlink) Following CVE-2025-31133 |
CWE-61 | Low | 1.14.3-1.el9_0 | 05.11.2025 |
SB2025110519 SB2025110530 SB2025110545 and 34 more |
||
| #VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-22871 |
CWE-444 | Medium | 1.20-4.rhaos4.18.el8 | 05.04.2025 |
SB2025040507 SB2025040508 SB2025040739 and 109 more |
||
| #VU105450 - Resource exhaustion CVE-2025-27144 |
CWE-400 | Medium | 1.20-2.rhaos4.18.el9 | 07.03.2025 |
SB2025030735 SB2025030736 SB2025030737 and 80 more |
||
| #VU103500 - Permissions, Privileges, and Access Controls CVE-2024-11218 |
CWE-264 | Medium | 1.17-2.rhaos4.16.el8, 1.17-2.rhaos4.16.el9, 1.19.1-1.rhaos4.17.el8 | 03.02.2025 |
SB2025020321 SB2025020332 SB2025020333 and 34 more |
||
| #VU101972 - Security Features CVE-2024-56326 |
CWE-254 | Low | 1.17-2.rhaos4.14.el8, 1.17-2.rhaos4.14.el9, 1.17-2.rhaos4.15.el8, 1.17-2.rhaos4.15.el9, 1.17-2.rhaos4.16.el8, 1.17-2.rhaos4.16.el9 | 27.12.2024 |
SB2024122789 SB2024122790 SB2024122791 and 78 more |
||
| #VU101971 - Security Features CVE-2024-56201 |
CWE-254 | Low | 1.17-2.rhaos4.14.el8, 1.17-2.rhaos4.14.el9, 1.17-2.rhaos4.15.el8, 1.17-2.rhaos4.15.el9, 1.17-2.rhaos4.16.el8, 1.17-2.rhaos4.16.el9 | 27.12.2024 |
SB2024122789 SB2025010203 SB2025010322 and 62 more |
||
| #VU98141 - Improper input validation CVE-2024-9341 |
CWE-20 | Low | 1.17-1.rhaos4.17.el8, 1.17-1.rhaos4.17.el9 | 08.10.2024 |
SB2024100842 SB2024100843 SB2024100848 and 44 more |
||
| #VU96055 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2024-42353 |
CWE-601 | Low | 1.17-1.rhaos4.14.el8, 1.17-1.rhaos4.14.el9, 1.17-1.rhaos4.16.el8, 1.17-1.rhaos4.16.el9 | 15.08.2024 |
SB2024081552 SB2024081555 SB2024081556 and 44 more |
||
| #VU94616 - Information Exposure Through Log Files CVE-2024-6104 |
CWE-532 | Low | 1.14.3-2.rhaos4.17.el8, 1.14.3-2.rhaos4.17.el9 | 19.07.2024 |
SB2024071927 SB2024071929 SB2024071930 and 83 more |
||
| #VU91159 - Improper input validation CVE-2024-24789 |
CWE-20 | Low | 1.14.3-2.rhaos4.17.el8, 1.14.3-2.rhaos4.17.el9 | 05.06.2024 |
SB2024060520 SB2024060635 SB2024060729 and 78 more |
||
| #VU87200 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-24785 |
CWE-79 | Low | 1.14.3-1.rhaos4.16.el8, 1.14.3-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 61 more |
||
| #VU87198 - Exposure of sensitive information to an unauthorized actor CVE-2023-45289 |
CWE-200 | Low | 1.14.3-1.rhaos4.16.el8, 1.14.3-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 54 more |
||
| #VU87197 - Resource exhaustion CVE-2023-45290 |
CWE-400 | Medium | 1.14.3-1.rhaos4.16.el8, 1.14.3-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 101 more |
||
| #VU86795 - Improper input validation CVE-2023-29483 |
CWE-20 | Medium | 1.14.3-1.rhaos4.16.el8, 1.14.3-1.rhaos4.16.el9 | 26.02.2024 |
SB2024022638 SB2024040115 SB2024042448 and 37 more |
Showing elements 1 - 20 out of 76