Google gVisor CVE-2026-95702 (CVSS 4.0 8.5): a use-after-free in the sandbox's VFS lets an ordinary container process run code in the host-side Sentry kernel; fixed in release 20260831.0
Google published CVE-2026-95702 on 9 October 2026 for gVisor, the user-space application kernel that sandboxes containers (runsc) and underpins services such as GKE Sandbox and some serverless platforms. A use-after-free in gVisor's VFS lets a local attacker with standard container privileges double-free the backing MemoryFile of an in-sandbox overlay filesystem and get code execution in the Sentry, the gVisor process that handles the sandboxed workload's system calls on the host. Google notes the Sentry stays confined by host seccomp filters and Linux namespaces, so this breaks the first layer of isolation rather than giving direct host root, but it is the step an attacker needs before chaining a host kernel bug. All platforms before release 20260831.0 (published 4 September) are affected; Google rates it CVSS 4.0 8.5. No exploitation reported. Primary: Google CVE record and gVisor fix commits.
- Product
- Google gVisor (runsc) container sandbox
- Versions
- All releases before 20260831.0, all platforms
- CVSS
- 8.5 (CVSS 4.0, Google)
- Exploited in Australia?
- unknown
- Patch to
- Update gVisor/runsc to release 20260831.0 or later on self-managed hosts; managed platforms using gVisor (e.g. GKE Sandbox) should confirm their node or runtime version. Keep host kernels patched, since this bug breaks only the first isolation layer.
Primary: CVE-2026-95702 — Google (CNA) record, gVisor VFS use-after-free (9 Oct 2026) · Vendor: gVisor release 20260831.0 · CVE: CVE-2026-95702 · gVisor fix commit 90bc4fc
