← All articles

Public exploit targets unpatched Ubuntu kernel flaw enabling container escape to host root

DepthFirst published research and exploit code for a Linux kernel use-after-free in the AF_UNIX socket subsystem, CVE-2026-80521, rated 7.8, that can escape a container and gain root on the host. The flaw sits in the garbage collector for file descriptors passed via SCM_RIGHTS, where a race condition can free linked sockets while a pointer remains on an internal list. AF_UNIX sockets are allowed by default in Docker and Kubernetes seccomp profiles, so the bug is reachable from inside a container. It was fixed upstream on August 6, but Ubuntu has not patched its 26.04, 24.04, or 22.04 LTS releases, including AWS, Azure, and GCP kernels. DepthFirst released a working exploit for 26.04.

Check
Track Ubuntu's kernel updates for 26.04, 24.04, and 22.04, apply them once available, and tighten seccomp and container isolation in the meantime.
Affected
Ubuntu LTS hosts on affected kernels let a process inside a container exploit the AF_UNIX use-after-free to escape and gain root on the host.
Fix
Apply Ubuntu kernel fixes when released, restrict untrusted container workloads, harden seccomp profiles, and monitor for the public exploit's behavior.