CVE-2026-96812
Awaiting Analysis Awaiting Analysis - Queue

Improper File Access in Google gVisor via CUSE

Vulnerability report for CVE-2026-96812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: Google Inc.

Description

Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google gvisor to 573a9e73cf844f (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-668 The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper exposure of a resource to the wrong sphere in the host file helper (gofer) component of Google gVisor. It affects Linux platforms with CUSE enabled and allows a local attacker with container image deployment privileges to gain root code execution on the host system. The attacker can include a /dev/cuse character device node in a container image, which passes through to the host when opened. This enables the attacker to register a host device and exploit unrestricted ioctl handling to overwrite root udev helper memory.

Impact Analysis

If you use Google gVisor with CUSE enabled on a Linux system, an attacker with container image deployment privileges could exploit this flaw to gain root access on your host system. This could lead to full system compromise, allowing the attacker to execute arbitrary code, steal data, install malware, or perform other malicious activities.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. If an attacker gains root access, they could exfiltrate or manipulate protected data, resulting in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Update gVisor to commit 573a9e73cf844f or later to address the improper exposure of resource to wrong sphere in the host file helper (gofer). Disable CUSE in your environment if not required, as this vulnerability specifically targets systems with CUSE enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart