diff --git a/recipes-containers/crun/crun/CVE-2026-88264.patch b/recipes-containers/crun/crun/CVE-2026-88264.patch
new file mode 100644
index 00000000..1d8eea96
--- /dev/null
+++ b/recipes-containers/crun/crun/CVE-2026-88264.patch
@@ -0,0 +1,109 @@
+From ef32479522af883568ce4a5482358069ff71dc8f Mon Sep 17 00:00:00 2001
+From: Giuseppe Scrivano <gscrivan@redhat.com>
+Date: Fri, 11 Sep 2026 09:25:48 +0000
+Subject: [PATCH] utils: do not follow symlinks when creating /dev/console
+
+create_file_if_missing_at() is only used to create `/dev/console` in the
+container rootfs when a terminal is requested, and it opened the file
+with O_CREAT but without O_NOFOLLOW.  A rootfs providing `/dev/console`
+as a symlink made the open follow it, and since the devices are created
+before the pivot_root the target was resolved against the host file
+system, so crun created a root owned file at a path chosen by the
+container image.
+
+Open the file with O_NOFOLLOW, and check for an already existing file
+without following symlinks either, so that a symlink is not mistaken for
+a regular file that is already there.
+
+This is only reachable when nothing is mounted over /dev, so the rootfs
+entry stays visible; the configurations generated by Docker, Podman,
+containerd, CRI-O and `crun spec` mount a tmpfs there.
+
+Add a test case.
+
+Fixes: CVE-2026-88264
+Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
+
+CVE: CVE-2026-88264
+Upstream-Status: Backport [https://github.com/containers/crun/commit/ef32479522af883568ce4a5482358069ff71dc8f]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/libcrun/utils.c   |  4 ++--
+ tests/test_devices.py | 36 ++++++++++++++++++++++++++++++++++++
+ 2 files changed, 38 insertions(+), 2 deletions(-)
+
+diff --git a/src/libcrun/utils.c b/src/libcrun/utils.c
+index ce44c261..76175411 100644
+--- a/src/libcrun/utils.c
++++ b/src/libcrun/utils.c
+@@ -196,14 +196,14 @@ get_file_type (mode_t *mode, bool nofollow, const char *path)
+ int
+ create_file_if_missing_at (int dirfd, const char *file, mode_t mode, libcrun_error_t *err)
+ {
+-  cleanup_close int fd_write = openat (dirfd, file, O_CLOEXEC | O_CREAT | O_WRONLY, mode);
++  cleanup_close int fd_write = openat (dirfd, file, O_CLOEXEC | O_CREAT | O_WRONLY | O_NOFOLLOW, mode);
+   if (fd_write < 0)
+     {
+       mode_t tmp_mode;
+       int ret;
+ 
+       /* On errors, check if the file already exists.  */
+-      ret = get_file_type_at (dirfd, &tmp_mode, false, file);
++      ret = get_file_type_at (dirfd, &tmp_mode, true, file);
+       if (ret == 0 && S_ISREG (tmp_mode))
+         return 0;
+ 
+diff --git a/tests/test_devices.py b/tests/test_devices.py
+index 6956e2bd..a99753a3 100755
+--- a/tests/test_devices.py
++++ b/tests/test_devices.py
+@@ -369,6 +369,41 @@ def test_mknod_char_device():
+         return -1
+     return 0
+ 
++def test_dev_console_symlink_does_not_escape_rootfs():
++    escaped = os.path.join(get_tests_root(), "escaped-console")
++
++    conf = base_config()
++    add_all_namespaces(conf)
++    conf['process']['terminal'] = True
++    conf['process']['args'] = ['/init', 'true']
++    conf['mounts'] = [i for i in conf['mounts'] if not i['destination'].startswith("/dev")]
++    # a hook forces the deferred pivot_root, so the rootfs is still reached
++    # through the host file system when the devices are created.
++    conf['hooks'] = {"createRuntime": [{"path": "/bin/true"}]}
++
++    def prepare_rootfs(rootfs):
++        os.symlink(escaped, os.path.join(rootfs, "dev", "console"))
++
++    output = None
++    try:
++        run_and_get_output(conf, callback_prepare_rootfs=prepare_rootfs)
++    except Exception as e:
++        output = e.output.decode()
++
++    if os.path.lexists(escaped):
++        logger.error("`%s` was created outside the rootfs", escaped)
++        return -1
++
++    if output is None:
++        logger.error("the container was not refused")
++        return -1
++
++    if "create file `console`" not in output:
++        logger.error("the container failed for a different reason: %s", output)
++        return -1
++
++    return 0
++
+ def test_dev_symlink_does_not_populate_outside_rootfs():
+     if is_rootless():
+         return (77, "requires root privileges")
+@@ -508,6 +543,7 @@ def test_allow_device_read_only():
+ all_tests = {
+     "mknod-fifo-device": test_mknod_fifo_device,
+     "mknod-char-device": test_mknod_char_device,
++    "dev-console-symlink-does-not-escape-rootfs": test_dev_console_symlink_does_not_escape_rootfs,
+     "dev-symlink-does-not-populate-outside-rootfs": test_dev_symlink_does_not_populate_outside_rootfs,
+     "allow-device-read-only": test_allow_device_read_only,
+     "owner-device" : test_owner_device,
diff --git a/recipes-containers/crun/crun_git.bb b/recipes-containers/crun/crun_git.bb
index 809b6c01..80468b0a 100644
--- a/recipes-containers/crun/crun_git.bb
+++ b/recipes-containers/crun/crun_git.bb
@@ -19,6 +19,7 @@ SRC_URI = "git://github.com/containers/crun.git;branch=main;name=crun;protocol=h
            file://0002-libocispec-fix-array-items-parsing.patch;patchdir=libocispec \
            file://CVE-2026-30892.patch \
            file://CVE-2026-47766.patch \
+           file://CVE-2026-88264.patch \
           "
 
 PV = "1.26.0+git"
