
New one from @pruvadev now that sandboxes are hot agian: CVE-2026-96812: gVisor directfs openHandle host-FD identity TOCTOU → guest-to-host sandbox escape follow-up to CVE-2026-96812, no separate CVE assigned https://www.pruva.dev/reproductions/REPRO-2026-00382 ``` production runsc --directfs=true --platform=systrap guest open(/race/target, O_RDWR|O_TRUNC) -> directfsInode.openHandle() unchecked openat() -> gofer preadv2/pwritev2 on the swapped host FD ```
