Containers Are No Longer a Security Boundary
DepthFirst showed CVE-2026-80521, a Linux AF_UNIX use-after-free, can escape containers sharing the host kernel.
DepthFirst argues containers are a weak isolation boundary because every container shares the host Linux kernel. They demonstrate escape with CVE-2026-80521, a heap use-after-free in AF_UNIX garbage collection of SCM_RIGHTS messages, discovered with their dfs-large1 model. A zero-day exploit for the bug won a Google kernelCTF slot on July 24, 2026, and the exploit code is on GitHub. They cite 5,976 Linux kernel CVEs in 2026 through mid-September and recommend Firecracker or Kata Containers for sensitive or untrusted workloads.
66