Executive brief
NVIDIA OpenShell is a container management and execution environment for Linux systems. A sandbox escape vulnerability allows attackers to break out of the intended container isolation, potentially gaining unauthorized code execution and full system access with escalated privileges.
Technical details
OpenShell for Linux contains a sandbox escape vulnerability (CVE-2026-65093) that allows an attacker to circumvent container isolation mechanisms. The vulnerability can be exploited to achieve arbitrary code execution outside the sandbox boundary, leading to privilege escalation, data tampering, and information disclosure. The attack vector and specific preconditions are not detailed in the available advisory text, but successful exploitation bypasses intended security boundaries. Patches are anticipated given the critical severity rating and public disclosure date of August 25, 2026.
Affected products
- NVIDIA OpenShell for Linux
Timeline
- 2026-08-25: disclosed