VendorsGooglegvisorall versions
Vulnerabilities

Google gVisor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-19333
pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RMID shmctl calls, because reference counting is mishandled.
Published 2018-11-17 · Modified
9.8EPSS 0.008
CVE-2025-2713
Improper File Permission Handling in Google gVisor runsc
Published 2025-03-28 · Analyzed
7.8EPSS 0.001
CVE-2018-16359
Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.
Published 2018-09-02 · Modified
7.1EPSS 0.005
CVE-2023-7258
Denial-of-Service in Gvisor
Published 2024-05-15 · Analyzed
6.5EPSS 0.002
CVE-2024-10603
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.
Published 2025-01-30 · Analyzed
6.3EPSS 0.003
CVE-2024-10026
Improved Seeding and Hashing In gVisor
Published 2025-01-30 · Analyzed
6.3EPSS 0.002
CVE-2018-20168
Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.
Published 2018-12-17 · Modified
5.5EPSS 0.003