CVE-2026-95702: high-severity vulnerability in Google gVisor
Code Execution in Host Sentry Process via Double Free in gVisor VFS MemoryFile
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5
exploitation probability
—
observed exploitation
nono source reports it
Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Google · gVisorRelated CVEs — Google gVisor
In the same product, most dangerous first.