Description
A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59652 | A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6 |
References
History
Tue, 22 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-08-02T08:57:35.072Z
Reserved: 2024-05-02T11:47:43.153Z
Link: CVE-2023-7258
Updated: 2024-08-02T08:57:35.072Z
Status : Analyzed
Published: 2024-05-15T17:15:09.987
Modified: 2025-07-22T21:06:27.080
Link: CVE-2023-7258
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:37Z
Weaknesses
EUVD