CVE-2026-96812: CWE-668 Exposure of Resource to Wrong Sphere in Google gVisor
CVE-2026-96812 is a high-severity vulnerability in Google gVisor affecting Linux platforms with CUSE enabled. It involves improper exposure of a resource in the host file helper (gofer), allowing a local attacker with container image deployment privileges to gain root code execution on the host. The attack vector includes embedding a /dev/cuse character device node in a container image, which passes through to the host and enables exploitation of unrestricted ioctl handling in CUSE to overwrite root udev helper memory.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-96812) in Google gVisor arises from improper exposure of the host file helper (gofer) resource to the wrong security sphere on Linux systems with CUSE enabled. A local attacker who can deploy container images can include a /dev/cuse character device node that is passed through to the host. This allows the attacker to register a host device and exploit unrestricted ioctl handling in CUSE, leading to memory overwrite of the root udev helper and ultimately root code execution on the host system. The vulnerability affects gVisor version 0. The CVSS 4.0 base score is 8.8, indicating high severity.
Potential Impact
A local attacker with container image deployment privileges can escalate privileges to root on the host system by exploiting this vulnerability. This compromises the host's security boundary, allowing full control over the host environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, restrict container image deployment privileges and avoid enabling CUSE on Linux platforms running gVisor if possible.
CVE-2026-96812: CWE-668 Exposure of Resource to Wrong Sphere in Google gVisor
Description
CVE-2026-96812 is a high-severity vulnerability in Google gVisor affecting Linux platforms with CUSE enabled. It involves improper exposure of a resource in the host file helper (gofer), allowing a local attacker with container image deployment privileges to gain root code execution on the host. The attack vector includes embedding a /dev/cuse character device node in a container image, which passes through to the host and enables exploitation of unrestricted ioctl handling in CUSE to overwrite root udev helper memory.
CVSS v4.0
Score 8.8high
Affected software
gVisor
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-96812) in Google gVisor arises from improper exposure of the host file helper (gofer) resource to the wrong security sphere on Linux systems with CUSE enabled. A local attacker who can deploy container images can include a /dev/cuse character device node that is passed through to the host. This allows the attacker to register a host device and exploit unrestricted ioctl handling in CUSE, leading to memory overwrite of the root udev helper and ultimately root code execution on the host system. The vulnerability affects gVisor version 0. The CVSS 4.0 base score is 8.8, indicating high severity.
Potential Impact
A local attacker with container image deployment privileges can escalate privileges to root on the host system by exploiting this vulnerability. This compromises the host's security boundary, allowing full control over the host environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, restrict container image deployment privileges and avoid enabling CUSE on Linux platforms running gVisor if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Date Reserved
- 2026-09-23T17:12:31.415Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab68d45f7a7c54106eb1379
Added to database: 09/25/2026, 15:03:33 UTC
Last enriched: 09/25/2026, 15:17:40 UTC
Last updated: 09/25/2026, 15:22:22 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.