Impact
An out of bounds read vulnerability exists in the grpcfuse kernel module installed within Docker Desktop’s Linux virtual machine. The flaw permits a local attacker who can write to /proc/docker entries to trigger the module to read beyond the boundary of a memory buffer. The CVE description specifies that the attacker could cause an unspecified impact, and no further details are provided.
Affected Systems
Docker Desktop for Windows, Linux, and macOS installations at or below version 4.61.0 are affected. The issue resides in the Linux VM that Docker Desktop embeds in these platforms, meaning any installation of these products at or below that version is at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score of less than 1 % shows a very low probability of exploitation in the wild. Docker Desktop has not listed this flaw in CISA KEV. An attacker must have local access to the host and the ability to write to /proc/docker entries to exploit the vulnerability, which is the only required foothold.
OpenCVE Enrichment