A vulnerability was found in containers crun up to 1.27 and classified as critical. The affected element is an unknown function of the component Device Setup. Such manipulation leads to symlink following.
This vulnerability is traded as CVE-2026-47766. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.