A public exploit targets CVE-2026-80521, a use-after-free vulnerability in the Linux kernel's AF_UNIX socket garbage collector that lets an unprivileged process escape a default Docker or Kubernetes container and obtain root privileges on its host. The bug leaves a stale scc_entry list pointer after a unix_vertex is freed, enabling the socket garbage-collection walk to dereference freed memory and bypass container namespace, cgroup, and seccomp isolation.
DepthFirst released research and working exploit code targeting Ubuntu 26.04; Ubuntu 26.04, 24.04, and 22.04 LTS—including affected cloud-kernel variants—reportedly had not distributed fixes. The vulnerability is reachable through ordinary AF_UNIX socket calls allowed by default Docker and Kubernetes seccomp profiles. Upstream fixed the issue in Linux 7.1.10 and 7.2; organizations should deploy patched host kernels and reboot, while using reduced capabilities, PFN-interface restrictions, resource limits, or microVM isolation as interim mitigations. No confirmed in-the-wild exploitation has been reported.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
DepthFirst published research and proof-of-concept exploit code for CVE-2026-80521 targeting Ubuntu 26.04. The exploit demonstrated that an unprivileged process in default Docker or Kubernetes configurations could escape a container and gain host-root access.
An upstream fix for the AF_UNIX garbage-collector use-after-free landed in Linux 7.1.10 and 7.2. The fix removes a vertex's cached SCC list entry before it can be freed, preventing later garbage-collection walks from dereferencing it.
DepthFirst reported the vulnerability later designated CVE-2026-80521 to the Linux kernel security team. An OpenAI researcher independently reported the same issue to kernel maintainers.
DepthFirst obtained a Google kernelCTF slot with its exploit for the AF_UNIX container-escape vulnerability.
The vulnerable AF_UNIX socket garbage-collector implementation was introduced in Linux kernel 6.10 and later backported to the Linux 6.1 and 6.6 stable branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.