Improper Resource Exposure in Google gVisor on Linux Platforms
CVE-2026-96812
8.8HIGH
What is CVE-2026-96812?
An improper exposure of resources in Google gVisor’s file helper (gofer) enables local attackers with container image deployment privileges to execute root code on the host system. This occurs specifically in environments with CUSE (Character Device in User Space) enabled. By including a /dev/cuse character device node in the container image, an attacker can leverage the unrestricted ioctl handling of CUSE to register a host device and manipulate the udev helper memory, thereby achieving elevated privileges.
Affected Version(s)
gVisor Linux 0 < 573a9e73cf844f