Google Donates gVisor to the CNCF; Ant Group, Modal and Tines Get Merge Rights
Security / news
Google Donates gVisor to the CNCF; Ant Group, Modal and Tines Get Merge Rights
The sandbox that sits between untrusted containers and the Linux kernel moves out of the google GitHub organization, under Apache 2.0.
Google is moving gVisor, its userspace Linux kernel for sandboxing containers and agent workloads, into the Cloud Native Computing Foundation at the Sandbox level, with merge rights for maintainers outside Google. The change affects who can approve code in a project that sits between untrusted code and the host kernel, not the security model itself.
Engineers Etienne Perot and Jing Chen announced the donation on Oct. 2 on the gVisor blog. The repository will move out of the google GitHub organization, and the licence stays Apache 2.0.
The timeline Google gave
The CNCF accepted the project on Sept. 28, three weeks after the Sept. 7 application. The target is Incubation "over coming months", but the post gives no date for it.
| Date (2026) | Step |
|---|---|
| Sept. 7 | Application submitted |
| Sept. 22 | CNCF review |
| Sept. 28 | Accepted at Sandbox level |
| Oct. 2 | Announcement |
What changes in governance
Merge permissions go to non-Google maintainers from Ant Group, Modal and Tines, and the project moves to org-based voting so Google cannot decide alone. OpenAI, Tencent and NVIDIA are listed as continuing contributors rather than maintainers.
Build and test infrastructure moves to GitHub Actions and Buildkite, and Google's internal infrastructure will stop blocking pull requests. Google says it will keep developing gVisor internally.
The CNCF's sandbox application names Google's own users as GKE, Gemini, Vertex AI, Cloud Run, Confidential Space, YouTube, BigQuery and Gmail. Outside Google it lists Ant Group, OpenAI, Anthropic, Modal and Tines as adopters.
Why Google says it is doing this
The post gives three reasons. Teams treat virtualization as a stand-in for security, which Google calls a "false dichotomy." Out-of-the-box performance suffers on I/O-heavy workloads, and kernel maintainers have rejected upstream patches partly because gVisor was wholly Google-owned. And Google sees uses, such as gVisor on macOS and sandboxing on desktop Linux, that do not fit its commercial priorities.
Those are Google's reasons, written in a project post and an application it wrote itself. The application describes gVisor as "the second most mature implementation of Linux, after Linux", which is a vendor claim and not a measurement.
What the security model is, and is not
gVisor's security page calls it a two-layer sandbox: the Sentry, its userspace kernel written in Go, then Linux seccomp, pivot_root and namespaces beneath it. Escaping means getting through both.
The project issues CVEs only for flaws that cross the sandbox boundary, where the attacker does not initially control the sandbox configuration, and that are specific to gVisor. A bug that needs a hostile configuration will not get an ID, so a CVE count understates what is fixed.
The security page does not list published audits, a bug bounty or vulnerability statistics. Operators comparing it with a hypervisor-based sandbox, or with an agent runtime such as NVIDIA's OpenShell, have no independent track record on that page to read.
The kernel it avoids exposing
A sandbox like this matters because the host kernel is the larger target: the Linux kernel is approaching 2,000 CVEs per release. gVisor reimplements the system call surface in Go so that a container talks to the Sentry instead.
The next check is the repository itself: the post says it will leave the google organization, and gives no date for the move.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 03Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 04Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.