Vulnerabilities
Vulnerable Software
Google:  >> Gvisor  >> 20231030.0  Security Vulnerabilities
Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-03-28
A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6
CVSS Score
4.8
EPSS Score
0.001
Published
2024-05-15


Contact Us

Shodan ® - All rights reserved