@thecybersecguru@infosec.exchange
2026-09-23 12:57 UTC
🚨 **CVE-2026-80521: Linux kernel container escape**
A public exploit chains an **AF_UNIX socket garbage-collector use-after-free** into host-level code execution from an unprivileged container.
The bug involves a race in the SCC garbage collector that leaves a freed `unix_vertex` reachable through a stale `scc_entry` pointer.
The PoC reportedly works against Ubuntu 26.04 and defeats several kernel hardening mechanisms.
Ubuntu 22.04, 24.04 and 26.04 are currently listed as affected in the article's September 23 update.
Technical breakdown + exploit chain:
https://thecybersecguru.com/news/cve-2026-80521-ubuntu-kernel-container-escape/
#Linux #Cybersecurity #ContainerSecurity #Docker #Kubernetes #CVE
Replies (0)
No replies.