CVE-2026-2664
Docker Desktop vulnerability analysis and mitigation

Overview

CVE-2026-2664 is an out-of-bounds read vulnerability in the grpcfuse kernel module present in the Linux VM component of Docker Desktop for Windows, Linux, and macOS. The flaw stems from improper validation of user-supplied data when handling procfs arguments, allowing a read past the end of an allocated buffer via writes to /proc/docker entries. All Docker Desktop versions up to and including 4.61.0 are affected across all three supported platforms. The vulnerability was published on February 24, 2026, and carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 6.8 (Medium) (Feedly, ZDI).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read): the grpcfuse kernel module inside Docker Desktop's Linux VM fails to properly validate user-supplied data when processing procfs arguments, enabling a read beyond the end of an allocated buffer. An attacker exploits this by writing to /proc/docker entries from within the Linux VM, triggering the out-of-bounds read in the kernel module. The attack vector is local, requires only low privileges, and no user interaction. A proof-of-concept advisory was published by Zero Day Initiative (ZDI-26-125) on February 25, 2026, detailing the lack of proper validation in procfs argument handling (ZDI, Feedly).

Impact

A local attacker with low-privilege code execution capability can exploit this vulnerability to disclose sensitive information from kernel memory and potentially escalate privileges. When chained with other vulnerabilities, the out-of-bounds read could be leveraged to execute arbitrary code in the context of the kernel within Docker Desktop's Linux VM. The impact spans all three supported platforms — Windows, Linux, and macOS — affecting confidentiality, integrity, and availability of the host environment (ZDI, Feedly).

Exploitability

A proof-of-concept exploit is publicly available via the Zero Day Initiative advisory (ZDI-26-125), published February 25, 2026. As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.014% (0.000140), indicating a currently low probability of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (ZDI, Feedly).

Exploitation steps

  1. Gain local access: Obtain low-privilege code execution within the Docker Desktop Linux VM on a target system running Docker Desktop ≤ 4.61.0 on Windows, Linux, or macOS.
  2. Identify the target interface: Locate the /proc/docker procfs entries exposed by the grpcfuse kernel module inside the Linux VM.
  3. Craft malicious write: Write specially crafted, malformed data to the /proc/docker procfs entries in a way that triggers improper argument handling in the grpcfuse kernel module.
  4. Trigger out-of-bounds read: The kernel module processes the malformed input without proper bounds validation, causing a read past the end of an allocated buffer in kernel memory.
  5. Extract sensitive data: Capture the out-of-bounds memory contents to disclose sensitive kernel memory information, which may include credentials, keys, or other privileged data.
  6. Chain for privilege escalation: Optionally combine the disclosed memory information with a secondary vulnerability to achieve kernel-level code execution or full privilege escalation (ZDI, Feedly).

Indicators of compromise

  • File System / procfs: Unusual or repeated writes to /proc/docker entries from low-privilege processes within the Docker Desktop Linux VM.
  • Logs: Kernel log entries (e.g., dmesg) showing memory access errors, kernel warnings, or crashes originating from the grpcfuse module.
  • Process: Unexpected low-privilege processes interacting with /proc/docker or spawning privileged child processes within the Docker Desktop Linux VM.
  • Network: Anomalous outbound connections from the Docker Desktop Linux VM following unexpected process activity, potentially indicating post-exploitation lateral movement.

Mitigation and workarounds

The primary remediation is to upgrade Docker Desktop to version 4.62.0 or later, which contains the fix for this vulnerability (Docker Release Notes). No configuration-based workaround has been officially published; until patching is possible, organizations should restrict access to systems running vulnerable Docker Desktop versions to trusted users only, since exploitation requires local code execution capability. Given the availability of a public PoC exploit and the privilege escalation risk, patching should be prioritized across all affected platforms (Windows, Linux, macOS) (ZDI, Feedly).

Community reactions

The Zero Day Initiative published advisory ZDI-26-125 on February 25, 2026, providing technical details and a CVSS score for the vulnerability. Docker's official security announcements page references the fix in the Docker Desktop 4.62.0 release notes. Community aggregators including Vulners, VulDB, and CIRCL's vulnerability database indexed the CVE shortly after disclosure, and a brief technical write-up appeared on infinitsec.net and systemtek.co.uk. No significant controversy or widespread social media discussion has been observed beyond standard vulnerability tracking (Docker Security, ZDI).

Additional resources


SourceThis report was generated using AI

Related Docker Desktop vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5843HIGH8.8
  • Docker Desktop logoDocker Desktop
  • cpe:2.3:a:docker:docker_desktop
NoYesMay 22, 2026
CVE-2026-5817HIGH8.8
  • Docker Desktop logoDocker Desktop
  • cpe:2.3:a:docker:docker_desktop
NoYesMay 22, 2026
CVE-2026-6406HIGH8.8
  • Docker Desktop logoDocker Desktop
  • cpe:2.3:a:docker:docker_desktop
NoYesMay 22, 2026
CVE-2026-8936HIGH8.2
  • Docker Desktop logoDocker Desktop
  • cpe:2.3:a:docker:docker_desktop
NoYesJun 02, 2026
CVE-2026-17106HIGH7.1
  • Docker logoDocker
  • openbao-fips
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management