ZDI-26-327: Docker Desktop grpcfuse Kernel Module Uncontrolled Recursion Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code within a container on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-8936.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-327?
The severity of ZDI-26-327 is rated as 27, indicating a high risk of denial-of-service exploitation.
How do I fix ZDI-26-327?
To address ZDI-26-327, update to the latest version of Docker Desktop that contains the necessary security patches.
What type of attack does ZDI-26-327 enable?
ZDI-26-327 enables a denial-of-service attack that can disrupt the functionality of Docker Desktop installations.
What permissions are needed to exploit ZDI-26-327?
An attacker must have the ability to execute low-privileged code within a container on the target system to exploit ZDI-26-327.
Is ZDI-26-327 specific to any version of Docker Desktop?
Yes, ZDI-26-327 affects specific installations of Docker Desktop; users should verify if they are using a vulnerable version.