ZDI-CAN-30796: ZDI-26-327: Docker Desktop grpcfuse Kernel Module Uncontrolled Recursion Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code within a container on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-8936.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30796?
The severity of ZDI-CAN-30796 is rated at 27, indicating a potential risk for denial-of-service attacks.
How do I fix ZDI-CAN-30796?
To fix ZDI-CAN-30796, ensure that you update your Docker Desktop installation to the latest available version that addresses this vulnerability.
What impact does ZDI-CAN-30796 have on Docker Desktop?
ZDI-CAN-30796 allows local attackers to create a denial-of-service condition on affected installations of Docker Desktop.
Who is affected by ZDI-CAN-30796?
Users of Docker Desktop who allow low-privileged code execution within their containers are at risk from ZDI-CAN-30796.
What is the nature of the exploit for ZDI-CAN-30796?
The exploit for ZDI-CAN-30796 involves uncontrolled recursion leading to a denial-of-service condition.