Skip to main content Skip to local navigation

Linux Kernel Container Escape Vulnerability (CVE-2026-80521)

 

A picture containing text  Description automatically generated

 

Information Security Advisory


A recently disclosed vulnerability (CVE-2026-80521) affects the Linux kernel AF_UNIX socket subsystem and may allow an attacker to escape a container and obtain root privileges on the host system.

Severity level:
CVSS Score: 7.8/High

Description:

CVE-2026-80521 is a use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem caused by a race condition in the garbage collection mechanism used to manage file descriptors passed through SCM_RIGHTS messages. An attacker with code execution inside a container can exploit the flaw to corrupt kernel memory, escape container isolation, and gain root privileges on the underlying host.

Affected Versions:

  • Ubuntu 26.04 LTS
  • Ubuntu 24.04 LTS
  • Ubuntu 22.04 LTS
  • Red Hat Enterprise Linux 10
  • Debian 12,13,14
  • Upstream Linux Kernel (All versions prior to official patch committed on Aug 6, 2026)

 

Impact:
Successful exploitation may allow attackers to obtain root privileges on the host operating system.

Resolution:
Apply vendor-provided kernel updates as soon as they become available. Monitor Ubuntu and vendor security advisories for package availability.

Reference:

https://nvd.nist.gov/vuln/detail/cve-2026-80521

https://access.redhat.com/security/cve/cve-2026-80521

https://ubuntu.com/security/CVE-2026-80521

https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html

https://www.suse.com/security/cve/CVE-2026-80521.html

https://www.linuxjournal.com/content/ubuntu-container-escape-vulnerability-gets-public-exploit-kernel-patch-arrives

 

UIT Information Security




Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web