CVE-2026-95702
Code Execution in Host Sentry Process via Double Free in gVisor VFS MemoryFile
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.
| CWE | CWE-416 CWE-415 |
| Vendor | |
| Product | gvisor |
| Ecosystems | |
| Industries | Technology |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for google gvisor
Be the first to know when new unknown vulnerabilities affecting google gvisor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google / gVisor
0 < 20260831.0
References
Credits
Mikhail Sosonkin from OpenAI