CVE-2026-8936: Docker Desktop
High severity, CVSS 8.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76.0.
Affected products
- Docker Docker Desktop: from 4.33.0, before 4.76.0 (fixed in 4.76.0)
Published 2026-06-02. Last modified 2026-07-22.