Use-After-Free Vulnerability in Google gVisor Allowing Code Execution
CVE-2026-95702

8.5HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-95702?

The vulnerability in Google gVisor stems from a use-after-free scenario within the Virtual File System (VFS). This issue permits a local attacker, granted standard container privileges, to execute arbitrary code in the host's sentry process. This occurs due to a double-free operation on the MemoryFile associated with an in-sandbox overlay filesystem. Despite the exploit potential, the execution remains confined within the security boundaries established by Linux seccomp and namespace protections on the host.

Affected Version(s)

gVisor Linux 0 < 20260831.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mikhail Sosonkin from OpenAI
.