CVE-2026-2664Disclosure(docker / desktop)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch docker desktop systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entries. The issue has been fixed in Docker Desktop 4.62.0 .

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • desktop

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-24); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
desktop

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-09-17: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-09-17: 102-2402-2702-2803-0109-17
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-02-271
General1
2026-02-281
Disclosure1
2026-03-011
Disclosure1
2026-09-171
Patch1
Full discourse5 posts
  • Threat Landscape@LandscapeThreat
    Patch

    Docker disclosed two Docker Sandboxes vulnerabilities that can allow malicious guest environments to escape workspace isolation and access host resources. CVE-2026-77179, affecting macOS versions before 0.42.0, enables symlink-race redirection of filesystem operations, potentially permitting arbitrary file read/write and host code execution. CVE-2026-79994, affecting versions before 0.42.0, can redirect guest-to-host Unix socket connections to unauthorized AF_UNIX sockets, enabling data disclosure or access to host-side functions. Docker recommends upgrading to 0.42.0 or later, using clone mode, removing writable host mounts, and minimizing sensitive data in shared paths. VULNERABILITY CVE-2026-17106 CVE-2026-2664 CVE-2026-28400 CVE-2026-33990 CVE-2026-5817 CVE-2026-5843 CVE-2026-77179 CVE-2026-79994

    Post summary

    Docker disclosed two sandbox escape vulnerabilities (CVE-2026-77179 and CVE-2026-79994) affecting macOS before version 0.42.0 and recommended upgrading to 0.42.0 or later, using clone mode, removing writable host mounts, and minimizing sensitive data.

    2004173
    98 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2664 (CVSS:6.8, HIGH) is Analyzed. An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows,..https://nvd.nist.gov/vuln/detail/CVE-2026-2664 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-2664, noting it as an out-of-bounds read in the grpcfuse kernel module used by Docker Desktop for Windows, but provides no evidence of exploitation, patches, or PoC.

    0000032
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2664 (CVSS:6.8, HIGH) is Analyzed. An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows,..https://nvd.nist.gov/vuln/detail/CVE-2026-2664 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2026‑2664 is flagged as a high‑severity out‑of‑bounds read vulnerability in the grpcfuse kernel module used in Docker Desktop for Windows, with CVSS 6.8 and an NVD reference.

    0000039
    173 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    General

    Docker Desktop grpcfuse Kernel Module Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2026-2664) #CVE20262664 #CyberSecurity #Docker #InformationDisclosureVulnerability https://www.systemtek.co.uk/?p=48550 https://t.co/syfHHzkymV

    Post summary

    The tweet merely announces CVE‑2026‑2664 and links to a blog article, with no additional technical or exploit details provided.

    0000046
    1.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2664 An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allo… https://www.cve.org/CVERecord?id=CVE-2026-2664

    Post summary

    The text announces CVE-2026-2664, an out-of-bounds read in the grpcfuse kernel module affecting Docker Desktop up to v4.61.0, with no PoC, exploit, or patch details provided.

    00000134
    56.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appdockerdesktop-linux-
Appdockerdesktop-macos-
Appdockerdesktop-windows-

Explore more