CyberRota Analysis
AI-GeneratedA vulnerability in the host file helper of Google gVisor on Linux platforms with CUSE enabled allows local attackers with container image deployment privileges to execute arbitrary code with root privileges on the host system. By including a /dev/cuse character device node in a container image, attackers can exploit improper handling of ioctl calls to manipulate host memory. Organizations utilizing gVisor for container security should prioritize patching this vulnerability to mitigate the risk of unauthorized access and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.