Security firm DepthFirst has released research and a working exploit for a Linux kernel use-after-free vulnerability in the AF_UNIX socket subsystem. Tracked as CVE-2026-80521 with a CVSS score of 7.8, the flaw can be used to escape a container and gain root privileges on the host system.
The vulnerability was fixed upstream on August 6, but the exploit is aimed at unpatched Ubuntu systems, highlighting a gap between the upstream fix and Ubuntu's release channel. Administrators running Ubuntu containers should watch for kernel updates and apply them as soon as they become available, since the public exploit lowers the barrier for attackers.