Google Cloud has published advisory GCP-2026-068 detailing a critical container isolation vulnerability (CVE-2026-49102, CVSS 9.3) within the gVisor (runsc) user-space kernel sandbox powering Google Cloud Run and GKE Sandbox workloads. The vulnerability allowed threat actors deploying containerized microservices to escape the virtualized container environment and execute unauthorized system calls directly against host worker nodes.
Vulnerability Analysis: VFS2 IPC Descriptor Race Condition (CWE-269)
Google Cloud Run executes untrusted customer containers inside gVisor, an application kernel written in Go that intercepts and implements Linux system calls in unprivileged user space. This architecture provides strong defense-in-depth against kernel zero-day exploits.
However, security researchers identified a concurrency flaw in the handling of Unix Domain Socket file descriptors across cloned IPC namespaces. By spawning high-frequency asynchronous threads that cycled epoll_wait and dup3 descriptors while triggering container memory reclamation, an attacker could induce a state where a guest socket mapped directly to a host IPC transport endpoint managed by the node daemon.
// Pseudocode of concurrent socket descriptor race condition in gVisor runsc
void *trigger_race(void *arg) {
int sfd = socket(AF_UNIX, SOCK_STREAM | SOCK_NONBLOCK, 0);
for (int i = 0; i < 100000; i++) {
dup3(sfd, TARGET_FD, O_CLOEXEC);
// Concurrently invoke epoll registration during namespace unshare
epoll_ctl(epfd, EPOLL_CTL_ADD, TARGET_FD, &ev);
}
return NULL;
}
Impact Scope: Multi-Tenant Cloud Isolation
In multi-tenant serverless environments, breaking out of container isolation compromises host node telemetry, instance metadata service (IMDS) endpoints, and co-located workloads. Google's internal security engineering teams patched the flaw globally across all production Cloud Run clusters within 48 hours of coordinated disclosure, confirming zero evidence of wild exploitation.
Remediation Guidance for GKE Operators
- Update Self-Managed gVisor Nodes: For clusters running GKE Sandbox, upgrade node pools to GKE release 1.32.4-gke.1100 or higher.
- Enforce Seccomp Profiles: Deploy Kubernetes admission controllers to block dangerous syscalls (such as
unshareandclone3) in container pods not requiring root capabilities. - Audit Node IMDS Access: Ensure Workload Identity is strictly enforced to prevent extracted pod tokens from assuming cluster node IAM permissions.



