CVE-2026-96812

Source
https://cve.org/CVERecord?id=CVE-2026-96812
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96812.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-96812
Published
2026-09-25T14:47:47Z
Modified
2026-09-27T03:48:39Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE
Details

Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.

Database specific
{
    "cna_assigner": "Google",
    "cwe_ids": [
        "CWE-269",
        "CWE-668"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96812.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "573a9e73cf844f"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/google/gvisor

Affected ranges

Type
GIT
Repo
https://github.com/google/gvisor
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96812.json"