vulnerability
Published 2026-10-09
Verified 2026-10-10

Google gVisor CVE-2026-95702 (CVSS 4.0 8.5): a use-after-free in the sandbox's VFS lets an ordinary container process run code in the host-side Sentry kernel; fixed in release 20260831.0

Google published CVE-2026-95702 on 9 October 2026 for gVisor, the user-space application kernel that sandboxes containers (runsc) and underpins services such as GKE Sandbox and some serverless platforms. A use-after-free in gVisor's VFS lets a local attacker with standard container privileges double-free the backing MemoryFile of an in-sandbox overlay filesystem and get code execution in the Sentry, the gVisor process that handles the sandboxed workload's system calls on the host. Google notes the Sentry stays confined by host seccomp filters and Linux namespaces, so this breaks the first layer of isolation rather than giving direct host root, but it is the step an attacker needs before chaining a host kernel bug. All platforms before release 20260831.0 (published 4 September) are affected; Google rates it CVSS 4.0 8.5. No exploitation reported. Primary: Google CVE record and gVisor fix commits.

Product
Google gVisor (runsc) container sandbox
Versions
All releases before 20260831.0, all platforms
CVSS
8.5 (CVSS 4.0, Google)
Exploited in Australia?
unknown
Patch to
Update gVisor/runsc to release 20260831.0 or later on self-managed hosts; managed platforms using gVisor (e.g. GKE Sandbox) should confirm their node or runtime version. Keep host kernels patched, since this bug breaks only the first isolation layer.

Primary: CVE-2026-95702 — Google (CNA) record, gVisor VFS use-after-free (9 Oct 2026) · Vendor: gVisor release 20260831.0 · CVE: CVE-2026-95702 · gVisor fix commit 90bc4fc

tech cloud