CVE-2026-8936

Desktop: Uncontrolled Recursion (CVE-2026-8936)

Description

Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76.0.

Metrics

Severity
high
no public PoC known
8.2
Source: nvd-v4
1.8 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-06-02 22:16 UTC
CWE-674

Weakness classes (CWE)

  • CWE-674Class

    Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-22 19:10 UTC· nvd@nist.gov
    • Translation: Title: Docker Desktop, Description: Se corrigió un pánico de VM causado por recursión ilimitada en el módulo del kernel grpcfuse cuando un contenedor creó directorios profundamente anidados en una carpeta de host montada por enlace y desencadenó un evento de invalidación de dentry. Este problema se ha solucionado en Docker Desktop 4.76.0.

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Docker

    Desktop4.76.0

References & sources

IDCVE-2026-8936