CVE-2026-8936: Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Docker Desktopto a version that resolves this vulnerability.Fixed in 4.76.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8936?
The severity of CVE-2026-8936 is rated as high with a CVSS score of 8.2.
What does CVE-2026-8936 affect?
CVE-2026-8936 affects the grpcfuse kernel module in Docker Desktop, specifically when handling deeply nested directory structures.
How do I mitigate CVE-2026-8936?
To mitigate CVE-2026-8936, users should upgrade to Docker Desktop version 4.76.0 or later where the issue has been fixed.
What can happen if CVE-2026-8936 is exploited?
Exploitation of CVE-2026-8936 can lead to a VM panic, causing the Docker Desktop environment to crash.
When was CVE-2026-8936 published?
CVE-2026-8936 was published on June 2, 2026.