CVE-2026-96812
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.
Weaknesses
CWE-269, CWE-668
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2025-71421PoC
- HIGHCVE-2026-100578PoC
- HIGHCVE-2026-100586PoC
- MEDIUMCVE-2026-100611PoC
- HIGHCVE-2026-100615PoC
- LOWCVE-2026-100620PoC
- HIGHCVE-2026-100686PoC
- MEDIUMCVE-2026-101086PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.