OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-95702 (CVSS 8.5)

NVD · officialPublished Oct 9, 2026Risk 37/100

Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.

CVSS
8.5
AV:LocalAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source