High severity7.8NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026
CVE-2026-2664
CVE-2026-2664
Description
An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entries. The issue has been fixed in Docker Desktop 4.62.0 .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <=4.61.0
Patches
Vulnerability mechanics
References
1- docs.docker.com/desktop/release-notes/nvdRelease Notes
News mentions
1- ZDI-26-125: Docker Desktop grpcfuse Kernel Module Out-Of-Bounds Read Information Disclosure VulnerabilityZero Day Initiative · Feb 25, 2026