Exploit Released for Unpatched Ubuntu Kernel Flaw CVE-2026-80521, Enabling Container Escape to Host Root
A use-after-free in the Linux kernel's AF_UNIX subsystem (CVE-2026-80521) allows containers to escape and gain root on the host; it is patched upstream but unpatched in Ubuntu LTS releases, and DepthFirst has released exploit code while arguing containers are…
A heap use-after-free in the Linux kernel's AF_UNIX socket subsystem, located in the garbage collection of SCM_RIGHTS messages (CVE-2026-80521), allows an attacker to escape from a container and gain root on the host. Because every container shares the host kernel, the escape bypasses namespaces, cgroups, and seccomp. Security firm DepthFirst discovered the bug using an AI model (dfs-large1) and released exploit code on GitHub targeting Ubuntu 26.04. The flaw is fixed upstream but remains unpatched in Ubuntu 26.04, 24.04, and 22.04 LTS releases, including cloud images on AWS, Azure, and GCP, affecting default Docker and Kubernetes environments. A zero-day exploit for the bug won a Google kernelCTF slot on July 24, 2026. The Hacker News reports no confirmed in-the-wild exploitation. DepthFirst also notes 5,976 Linux kernel CVEs recorded in 2026 through mid-September and recommends Firecracker or Kata Containers for sensitive or untrusted workloads. The two reports do not materially disagree; the Hacker News account focuses on the unpatched Ubuntu exposure and released exploit, while the later Lobsters report adds technical root-cause detail, the kernelCTF zero-day win, and the broader argument that containers are a weak isolation boundary.
- CVE-2026-80521 is a heap use-after-free in the Linux kernel's AF_UNIX socket subsystem, specifically in the garbage collection of SCM_RIGHTS messages.
- The flaw enables container escape to gain root on the host, bypassing namespaces, cgroups, and seccomp because all containers share the host kernel.
- The bug is patched upstream but unpatched in Ubuntu 26.04, 24.04, and 22.04 LTS, including cloud images on AWS, Azure, and GCP; default Docker and Kubernetes environments are affected.
- Security firm DepthFirst discovered the vulnerability with an AI model (dfs-large1) and released exploit code on GitHub, targeting Ubuntu 26.04.
- A zero-day exploit for CVE-2026-80521 won a Google kernelCTF slot on July 24, 2026.
- The Hacker News reports no confirmed in-the-wild exploitation of the flaw to date.
- DepthFirst cites 5,976 Linux kernel CVEs in 2026 through mid-September and recommends Firecracker or Kata Containers for sensitive or untrusted workloads.
Coverage timelineoldest first · each row is one article
- · 6d agoExploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
The Hacker News· 85
Unpatched Linux kernel flaw (CVE-2026-80521) enables container escape to host root, with exploit code released for Ubuntu.
- · 1d agoContainers Are No Longer a Security Boundary
Lobsters · security· 66
DepthFirst showed CVE-2026-80521, a Linux AF_UNIX use-after-free, can escape containers sharing the host kernel.
Vulnerabilities in this storyAll →
- CVE-2026-805217.8<1%Linux kernel: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partiallypublished · Linux kernel
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-80521 | Linux kernel: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a small window where unix_add_edges() publishes a new edge (B B) to GC but its skb is not queued by skb_queue_tail(). If 2-2) completes before skb_queue_tail() and GC is triggered, it judges A B as dead, but B is not freed because GC cannot collect the not-yet-queued skb holding the B B edge. X -. A B -. This edge is visible ^--' ^..' but skb is not This itself is not a problem since the next GC run will judge B as dead as well and free it finally. X -. A B -. ^--' ^--' However, X's SCC forces the next GC to call unix_walk_scc_fast(), and it iterates over A through B's scc_entry. Let's unlink scc_entry before freeing the vertex in unix_del_edge(). |