depthfirst.com Critical Linux Kernel Flaw Allows Container Escape via CVE-2026-80521
Article Content
- •CVE-2026-80521 allows container escape, impacting multiple Ubuntu LTS versions.
- •Exploit code has been released, increasing the risk of potential attacks.
- •Organizations should transition to stronger isolation methods like microVMs.
A use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem, tracked as CVE-2026-80521, enables attackers to escape containers and gain root access on the host system. Discovered by DepthFirst using their AI model dfs-large1, the flaw affects Ubuntu 26.04, 24.04, and 22.04 LTS releases, which have not yet received patches. The vulnerability was published on August 26, 2026, and has a CVSS score of 7.8. DepthFirst has released exploit code targeting Ubuntu 26.04, and the flaw is reachable through standard system calls allowed within containers, bypassing various isolation mechanisms. Organizations are advised to migrate untrusted workloads to microVM isolation technologies like Firecracker or Kata Containers. As of now, there are no confirmed reports of active exploitation, but the vulnerability poses a significant risk to multi-tenant environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Depthfirst and CVE-2026-52910 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Linux Kernel Vulnerabilities Affecting Ubuntu Systems Multiple critical vulnerabilities have been discovered in the Linux kernel affecting Ubuntu systems, particularly in versions 24.04 and 26.04 LTS. The vulnerabilities include CVE-2025-10263, which allows local attackers to bypass memory protections and escalate privileges on affected Arm and AMD processors. The issues…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…