CVE-2026-95702

EUVD-2026-95816
Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GoogleCNA
8.5 HIGH
LOCAL
LOW
LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 0.24%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
googlegvisor
𝑥
< 20260831.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
golang-gvisor-gvisor
bookworm
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable