Close Menu
NCIJ Network NCIJ Network
    What's Hot

    NASA Selects Far-Infrared Telescope as First in New Mission Class

    September 24, 2026

    A ‘devil-like’ flower from Thailand is new to science — and critically endangered

    September 24, 2026

    Germany Under Friedrich Merz Has Lost Its Authority at Home and Abroad

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • NASA Selects Far-Infrared Telescope as First in New Mission Class
    • A ‘devil-like’ flower from Thailand is new to science — and critically endangered
    • Germany Under Friedrich Merz Has Lost Its Authority at Home and Abroad
    • Dance Monkey v the NRL: did Tones and I really turn down $90,000 a minute because she hates her own song? | NRL
    • Lidl banned from selling copycat Birkenstock sandals, Dutch court rules
    • Labour’s last chance? The people shaping Andy Burnham’s grand plans for Britain | Andy Burnham
    • Dopamine sites: India and the world are discovering the thrill of shopping without buying
    • Hackers start exploiting critical WordPress flaw for code execution
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 23, 2026Vulnerability / Linux

    A use-after-free in the Linux kernel’s AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.

    The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst released exploit code targeting Ubuntu 26.04.

    Ubuntu’s security tracker lists the Linux package on 26.04 as “vulnerable, work in progress.” The 24.04 and 22.04 releases are also affected through newer kernel packages, including those for AWS, Azure, and GCP workloads. No fix has shipped on any affected release.

    The flaw is not in CISA’s Known Exploited Vulnerabilities catalog, and there are no confirmed reports of attacks using it.

    Cybersecurity

    The vulnerability sits in the kernel’s garbage collector for AF_UNIX sockets. That collector cleans up file descriptors passed between processes through SCM_RIGHTS messages. AF_UNIX sockets handle local communication between processes and are allowed by default in Docker and Kubernetes seccomp profiles, which is why the flaw can be reached from inside a container.

    A race condition in the garbage collector lets it see new references before the data carrying them has been queued. If the collector runs during that window, it can free part of a group of linked sockets without removing a pointer from a persistent internal list. The next collection pass follows that pointer into freed memory.

    Because the exploit reaches the kernel through ordinary system calls that containers are allowed to make, it bypasses namespace isolation, cgroup limits, and seccomp filtering.

    The upstream fix landed on August 6 in mainline kernel 7.2 and stable branch 7.1.10. The vulnerable code was introduced in kernel 6.10 and also backported to stable branches 6.1 and 6.6. Organizations running an affected kernel can apply the upstream patch directly. Ubuntu’s tracker shows “work in progress” with no published date for the distribution update.

    Neither DepthFirst nor Ubuntu has published a temporary workaround. DepthFirst recommends moving untrusted workloads to microVM isolation, such as Firecracker or Kata Containers, which give each workload its own kernel rather than sharing the host’s.

    How the Flaw Was Found

    DepthFirst said its AI model, dfs-large1, trained for vulnerability detection, found the flaw alongside a human-operated testing harness. The company won a Google kernelCTF slot with the exploit on July 24 and reported the bug to the kernel security team on August 5.

    The kernel maintainers replied that a researcher at OpenAI had independently reported the same bug, according to DepthFirst’s timeline. The CVE commit credits kernel-exploitation researcher Kyle Zeng as the reporter.

    Cybersecurity

    The disclosure is the latest in a series of 2026 kernel flaws that allow attackers to escape containers. A futex vulnerability disclosed in July and a flaw in the kernel’s cryptographic subsystem in April also allowed an unprivileged user to escalate to root on the host. Both discoveries involved AI-assisted research.

    DepthFirst argues that AI-accelerated vulnerability discovery has lowered the barrier to container escapes to the point that organizations should not treat containers as a security boundary.

    “The barrier to escaping containers by attacking the kernel has fallen so significantly that we must assume attackers can do so at will,” the company said.

    Nearly 5,700 Linux kernel CVEs have been published in 2026, the highest annual total on record, according to LinuxCVETracker. The demonstrated exploit and the rising volume are the basis for the company’s assessment.

    container Enabling Escape exploit Flaw HostRoot Linux Released Ubuntu unpatched
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers start exploiting critical WordPress flaw for code execution

    Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

    545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

    New RemControl Android banking malware targets users in Europe and Canada

    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    White hats recover 52 Bitcoin from Coldcard exploit, and a new public portal lets victims check eligibility

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    NASA Selects Far-Infrared Telescope as First in New Mission Class

    September 24, 2026

    A ‘devil-like’ flower from Thailand is new to science — and critically endangered

    September 24, 2026

    Germany Under Friedrich Merz Has Lost Its Authority at Home and Abroad

    September 24, 2026

    Dance Monkey v the NRL: did Tones and I really turn down $90,000 a minute because she hates her own song? | NRL

    September 24, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    NASA Selects Far-Infrared Telescope as First in New Mission Class

    September 24, 2026

    A ‘devil-like’ flower from Thailand is new to science — and critically endangered

    September 24, 2026

    Germany Under Friedrich Merz Has Lost Its Authority at Home and Abroad

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.