CVE-2026-2664
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows a local attacker to read sensitive data from the Docker Desktop environment on Windows, Linux, and macOS, potentially leading to unauthorized access or manipulation of system information. It affects versions up to 4.61.0, so users should upgrade to 4.62.0 or later to protect against this issue.
Technical Description
An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entries. The issue has been fixed in Docker Desktop 4.62.0 .
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 24, 2026
about 1 month ago
Last Modified
Feb 27, 2026
about 1 month ago
Vendor
docker
Product
desktop