DepthFirst published research and exploit code for a Linux kernel use-after-free in the AF_UNIX socket subsystem, CVE-2026-80521, rated 7.8, that can escape a container and gain root on the host. The flaw sits in the garbage collector for file descriptors passed via SCM_RIGHTS, where a race condition can free linked sockets while a pointer remains on an internal list. AF_UNIX sockets are allowed by default in Docker and Kubernetes seccomp profiles, so the bug is reachable from inside a container. It was fixed upstream on August 6, but Ubuntu has not patched its 26.04, 24.04, or 22.04 LTS releases, including AWS, Azure, and GCP kernels. DepthFirst released a working exploit for 26.04.
Researcher Asim Manizada published working exploit code on September 18 for four Linux kernel local privilege escalation flaws, each letting a local user gain root. The bugs are DirtyAH6 in IPsec AH6, TUNderflow in TUN/TAP, PPPoEject in PPPoE, and DiagSpill in SCTP diagnostics. Kernel maintainers fixed all four in recent weeks after a coordinated hold with distributions, and no in-the-wild abuse has been reported. Three require unprivileged user namespaces, which many distributions enable by default, while DiagSpill needs only an available SCTP module. The exploits are tuned to specific builds and can crash machines, but public code raises risk on shared multi-user systems.