PT-2026-98870 · Google · Gvisor

·

CVE-2026-96812

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

8.8

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Google gVisor versions prior to commit 573a9e73cf844f
Description An improper exposure of resource to the wrong sphere exists in the host file helper (gofer) on Linux platforms with CUSE (Character device for Userspace) enabled. A local attacker with container image deployment privileges can achieve root code execution on the host system by including a /dev/cuse character device node in a container image. Opening this device allows the sandboxed attacker to register a host device and exploit unrestricted ioctl (input/output control) handling to overwrite root udev helper memory.
Recommendations Update Google gVisor to commit 573a9e73cf844f or a later version.

Fix

Exposure of Resource to Wrong Sphere

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96812

Affected Products

Gvisor