Vulnerability Description
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
Related Weaknesses (CWE)
References
- https://docs.docker.com/ai/sandboxes/
- https://docs.docker.com/ai/sandboxes/security/isolation/
- https://github.com/docker/sbx-releases/releases/tag/v0.42.0
FAQ
What is CVE-2026-77179?
CVE-2026-77179 is a documented vulnerability. On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a sym...
How severe is CVE-2026-77179?
CVSS scoring is not yet available for CVE-2026-77179. Check NVD for updates.
Is there a patch for CVE-2026-77179?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.