importantSYS.SOURCE: The Hacker News• 2026-09-23T16:42:18+05:30
Exploit for Unpatched Ubuntu Linux Kernel Flaw Enables Container Escape to Host Root
An unpatched Linux kernel vulnerability (CVE-2026-80521) in Ubuntu allows container escape to host root privileges, with exploit code publicly released. The flaw remains unpatched in LTS versions despite upstream fixes, prompting recommendations for microVM isolation.
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.
The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst
*** END OF TRANSMISSION ***