Skip to main content Skip to local navigation

Linux Kernel Container Escape Vulnerability (CVE-2026-80521)

A recently disclosed vulnerability (CVE-2026-80521) affects the Linux kernel AF_UNIX socket subsystem and may allow an attacker to escape a container and obtain root privileges on the host system.


Severity level:
CVSS Score: 7.8/High

Description:

CVE-2026-80521 is a use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem caused by a race condition in the garbage collection mechanism used to manage file descriptors passed through SCM_RIGHTS messages. An attacker with code execution inside a container can exploit the flaw to corrupt kernel memory, escape container isolation, and gain root privileges on the underlying host.


Affected Versions:

  • Ubuntu 26.04 LTS.
  • Ubuntu 24.04 LTS.
  • Ubuntu 22.04 LTS.
  • Red Hat Enterprise Linux 10.
  • Debian 12,13,14.
  • Upstream Linux Kernel (All versions prior to official patch committed on Aug 6, 2026).

Impact:

Successful exploitation may allow attackers to obtain root privileges on the host operating system.

Resolution:

Apply vendor-provided kernel updates as soon as they become available. Monitor Ubuntu and vendor security advisories for package availability.

Reference:

https://nvd.nist.gov/vuln/detail/cve-2026-80521

https://access.redhat.com/security/cve/cve-2026-80521

https://ubuntu.com/security/CVE-2026-80521

https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html

https://www.suse.com/security/cve/CVE-2026-80521.html

https://www.linuxjournal.com/content/ubuntu-container-escape-vulnerability-gets-public-exploit-kernel-patch-arrives

UIT Information Security