Security Advisory

CVE-2026-77179

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 13:32:41
Last updated 2026-09-15 21:43:07
Assigner Docker
CVSS score 9.4
State PUBLISHED

Description

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.