A high-severity Linux kernel use-after-free vulnerability, tracked as CVE-2026-53361 (CVSS 7.1), affects the AF_UNIX socket garbage collector and can allow an unprivileged local attacker to corrupt kernel memory and escape a container. The flaw is a race condition in which concurrent MSG_PEEK operations retain a reference to an in-flight file descriptor that the garbage collector fails to account for, potentially leaving a dangling sk_buff after a live socket is freed.
Technical details and public proof-of-concept exploit code, including work described as BAD_GARBAGE.c, have been released. No confirmed in-the-wild exploitation has been reported, but organizations running shared, multi-tenant, or containerized Linux environments should apply upstream or stable backport fixes—available in stable kernel version 6.12.95 and later—then reboot affected hosts; access by untrusted local users should be restricted until patching is complete.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Kernel maintainer Kuniyuki Iwashima authored an upstream fix that sets gc_in_progress inside unix_gc() to prevent the race condition. The fix was included in stable commit d82ba05263c6 and backports, including Linux stable kernel 6.12.95.
Researcher sgkdev published technical details and proof-of-concept exploit code for CVE-2026-53361, a high-severity Linux AF_UNIX garbage-collector use-after-free that can enable local kernel-memory corruption and container escape. No confirmed in-the-wild exploitation was reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.