๐Ÿ” CVE Alert

CVE-2026-96812

UNKNOWN 0.0

Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.

CWE CWE-668 CWE-269
Vendor google
Product gvisor
Ecosystems
Industries
Technology
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for google gvisor

Be the first to know when new unknown vulnerabilities affecting google gvisor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google / gVisor
0 < 573a9e73cf844f

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/google/gvisor/commit/573a9e73cf844f

Credits

Anthropic (using Claude)