Skip to content
Critical Linux Kernel Flaw Allows Container Escape via CVE-2026-80521

Critical Linux Kernel Flaw Allows Container Escape via CVE-2026-80521

First seen 24 Sep 2026, 08:55 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 08:28 UTC
  • •CVE-2026-80521 allows container escape, impacting multiple Ubuntu LTS versions.
  • •Exploit code has been released, increasing the risk of potential attacks.
  • •Organizations should transition to stronger isolation methods like microVMs.

A use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem, tracked as CVE-2026-80521, enables attackers to escape containers and gain root access on the host system. Discovered by DepthFirst using their AI model dfs-large1, the flaw affects Ubuntu 26.04, 24.04, and 22.04 LTS releases, which have not yet received patches. The vulnerability was published on August 26, 2026, and has a CVSS score of 7.8. DepthFirst has released exploit code targeting Ubuntu 26.04, and the flaw is reachable through standard system calls allowed within containers, bypassing various isolation mechanisms. Organizations are advised to migrate untrusted workloads to microVM isolation technologies like Firecracker or Kata Containers. As of now, there are no confirmed reports of active exploitation, but the vulnerability poses a significant risk to multi-tenant environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-06-19
CVE-2026-52910 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-26
CVE-2026-80521 published
A use-after-free vulnerability in the Linux kernel's AF_UNIX subsystem was disclosed, impacting container security.
depthfirst.com
2026-09-17
First public PoC released
DepthFirst released exploit code targeting the CVE-2026-80521 vulnerability, increasing risk for affected systems.
Thehackernews
2026-09-22
DepthFirst research published
DepthFirst detailed the vulnerability and its implications for container security in a research post.
depthfirst.com
Recent
Ubuntu patch status unclear
Ubuntu's security tracker indicates the affected kernel package is 'vulnerable, work in progress' with no fix released yet.
Thehackernews

More articles in this cluster (4)

Following this threat?

Track Depthfirst and CVE-2026-52910 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed