Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.
{
"cna_assigner": "Google",
"cwe_ids": [
"CWE-269",
"CWE-668"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96812.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "573a9e73cf844f"
}
],
"source": "AFFECTED_FIELD"
}
]
}