Unrated severityNVD Advisory· Published Feb 24, 2026· Updated Feb 26, 2026
Out of bounds read vulnerability in grpcfuse kernel module
CVE-2026-2664
Description
An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entries. The issue has been fixed in Docker Desktop 4.62.0 .
Affected products
2- Docker/Docker Desktopv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- ZDI-26-125: Docker Desktop grpcfuse Kernel Module Out-Of-Bounds Read Information Disclosure VulnerabilityZero Day Initiative · Feb 25, 2026