Docker Sandboxes macOS virtio-fs escape CVE-2026-77179 (CVSS 9.4) + UDS relay CVE-2026-79994 (8.7); fix 0.42.0
Docker security announcements (Sandboxes 0.42.0; NVD received CVE-2026-77179 on 15 September 2026) document two sandbox-escape flaws. CVE-2026-77179 (Critical, Docker CVSS 4.0 base 9.4): on macOS the virtio-fs host server followed symlinks when reopening an unlinked file from a stored path, so malicious guest code (e.g. a compromised AI coding agent inside sbx) could escape the shared project workspace and read/modify arbitrary host files as the VMM user — potentially host code execution. Affects Sandboxes 0.28.0 up to but not including 0.42.0 on macOS. Companion CVE-2026-79994 (High, CVSS 4.0 8.7): guest-to-host Unix-domain socket relay TOCTOU symlink race; affects 0.37.0 through 0.41.9. Both fixed in 0.42.0 (release notes / sbx-releases tag). Docker reports no exploitation; CISA SSVC exploitation none; not in KEV at wire check. Workaround if unable to upgrade: use clone mode and avoid additional host mounts. Category vulnerabilities with AI-agent sandbox tag. Primary: Docker security announcements; secondary: NVD / GitHub sbx-releases v0.42.0.
- Product
- Docker Sandboxes (sbx) — AI coding-agent VMs; macOS virtio-fs host path (77179)
- Versions
- CVE-2026-77179: 0.28.0 ≤ ver < 0.42.0 on macOS. CVE-2026-79994: 0.37.0–0.41.9. Fixed: 0.42.0+
- CVSS
- (CVE-2026-77179 CVSS 4.0); 8.7 (CVE-2026-79994 CVSS 4.0)
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H (77179); CVSS:4.0 - Exploited in Australia?
- unknown
- Patch to
- Upgrade Docker Sandboxes to 0.42.0 or later; if blocked, use clone mode and avoid extra host mounts per Docker advisory
Primary: Docker — Sandboxes 0.42.0 security update (CVE-2026-77179 / CVE-2026-79994) · Vendor: docker/sbx-releases — v0.42.0 · CVE: CVE-2026-77179, CVE-2026-79994 · NVD — CVE-2026-77179; companion CVE-2026-79994
