gVisor Gofer Host File Helper CUSE I/OCTL RCE via /dev/cuse Exposure
CVE-2026-96812 Published on September 25, 2026
Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE
Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.
Vulnerability Analysis
CVE-2026-96812 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Types
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Improper Privilege Management
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2026-96812
Want to know whenever a new CVE is published for Google Gvisor? stack.watch will email you.
Affected Versions
Google gVisor:- Before 573a9e73cf844f is affected.