Exploit for unpatched Ubuntu kernel container escape
π A use-after-free bug in the Linux kernel's AF_UNIX socket garbage collector (CVE-2026-80521) can be abused to escape containers and gain host root, DepthFirst reported on September 22. The flaw was fixed upstream on August 6, but Ubuntu has not yet shipped patches for 26.04, 24.04, or 22.04 LTS; DepthFirst released exploit code targeting Ubuntu 26.04. The vulnerability is reachable from containers because AF_UNIX is allowed by default in common Docker and Kubernetes seccomp profiles, and no distro workaround has been published.
