REDHAT-BUG-2548382: High severity gVisor gvproxy vulnerability

Published Oct 9, 2026
·
Updated

A path-traversal flaw was found in gvproxy (gvisor-tap-vsock) in the port-forwarder's /services/forwarder/expose REST endpoint. When invoked with protocol=unix, the caller-supplied local field was passed without any validation to os.Remove() followed by net.Listen("unix", ...) on the host filesystem. Because this endpoint is exposed unauthenticated on the VM gateway (192.168.127.1:80), a process inside the guest VM — including an unprivileged container — could send a single HTTP POST to delete an arbitrary file owned by the gvproxy user on the host and replace it with a unix-socket inode. This crosses the container/VM-to-host isolation boundary, allowing destruction of sensitive host files (SSH keys, kubeconfig, shell/registry configuration) and denial of service. The issue was fixed by removing the os.Remove() call so pre-existing files can no longer be deleted or overwritten.

Affected Software

1 affected component
gVisor gvproxy

Event History

Oct 9, 2026
Data Sourced
via Red Hat·07:41 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

Any process inside the guest VM that can reach the VM gateway at 192.168.127.1:80 can invoke the affected endpoint without authentication. The description specifically includes unprivileged containers running inside the guest VM.

2

What access does an attacker need?

The attacker needs the ability to send a single HTTP POST to the port-forwarder expose endpoint with protocol=unix. No authentication to that endpoint is required.

3

What is the impact on the host?

An attacker can delete arbitrary files owned by the gvproxy user and replace them with a Unix socket inode. This can destroy sensitive host files, including SSH keys, kubeconfig, and shell or registry configuration, and can cause denial of service.

4

What changes in the fix?

The fix removes the os.Remove() call used before creating the Unix socket. Pre-existing host files can therefore no longer be deleted or overwritten through this endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203