Improper Resource Exposure in Google gVisor on Linux Platforms
CVE-2026-96812

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-96812?

An improper exposure of resources in Google gVisor’s file helper (gofer) enables local attackers with container image deployment privileges to execute root code on the host system. This occurs specifically in environments with CUSE (Character Device in User Space) enabled. By including a /dev/cuse character device node in the container image, an attacker can leverage the unrestricted ioctl handling of CUSE to register a host device and manipulate the udev helper memory, thereby achieving elevated privileges.

Affected Version(s)

gVisor Linux 0 < 573a9e73cf844f

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anthropic (using Claude)
.