๐Ÿ” CVE Alert

CVE-2026-95702

UNKNOWN 0.0

Code Execution in Host Sentry Process via Double Free in gVisor VFS MemoryFile

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.

CWE CWE-416 CWE-415
Vendor google
Product gvisor
Ecosystems
Industries
Technology
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for google gvisor

Be the first to know when new unknown vulnerabilities affecting google gvisor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google / gVisor
0 < 20260831.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/google/gvisor/commit/90bc4fc36fe442257a06ba15df00371561c183ed github.com: https://github.com/google/gvisor/commit/25c75149bc0eeaa6a3a49b9bbe3473588b2af6df github.com: https://github.com/google/gvisor/commit/e4efb89c787ef15b09e68d561f1303380e1d5a77

Credits

Mikhail Sosonkin from OpenAI