VYPR
High severity8.6NVD Advisory· Published Nov 13, 2019· Updated Jun 17, 2026

CVE-2019-18837

CVE-2019-18837

Description

An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Containers/Crunllm-fuzzy
    Range: <0.10.5
  • crun/crunv5
    Range: before 0.10.5
  • cpe:2.3:a:crun_project:crun:*:*:*:*:*:*:*:*
    Range: <0.10.5
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.