CVE-2026-96812

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets1 URL
By indicator
Full discourse1 post
  • Giuseppe `N3mes1s`@N3mes1s

    New one from @pruvadev now that sandboxes are hot agian: CVE-2026-96812: gVisor directfs openHandle host-FD identity TOCTOU → guest-to-host sandbox escape follow-up to CVE-2026-96812, no separate CVE assigned https://www.pruva.dev/reproductions/REPRO-2026-00382 ``` production runsc --directfs=true --platform=systrap guest open(/race/target, O_RDWR|O_TRUNC) -> directfsInode.openHandle() unchecked openat() -> gofer preadv2/pwritev2 on the swapped host FD ```

    12041178
    13.5K followersView on X

Explore more