Linux kernel AF_UNIX socket use-after-free security flaw (CVE-2026-80521)
Vulnerability
Summary
Hide ▲
Show ▼
Exploit code for CVE-2026-80521 exposed Ubuntu 26.04, 24.04, and 22.04 LTS systems to container-escape risk through a Linux kernel AF_UNIX socket use-after-free. The flaw can let an attacker break out of a container and reach root on the host, and DepthFirst said it targeted Ubuntu 26.04. The bug was fixed upstream on August 6, but Ubuntu had not shipped the patch for the affected releases.
Related Happenings
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
Vulnerability
H score30
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
VulnerabilityAbout this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector Action
H score37
First: 03.05.2026 09:26
Last: 03.05.2026 09:26
Sources 1
About this happening:
CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector ActionAbout this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/Mitigation
H score39
First: 30.04.2026 12:24
Last: 30.04.2026 12:24
Sources 1
About this happening:
Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/MitigationAbout this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Linux kernel AppArmor confused deputy vulnerabilities CrackArmor security flaw
Vulnerability
H score56
First: 13.03.2026 10:18
Last: 13.03.2026 10:18
Sources 1
About this happening:
Researchers disclosed CrackArmor, nine confused deputy flaws in the Linux kernel's AppArmor module that can let unprivileged users bypass protections, gain root*...
Linux kernel AppArmor confused deputy vulnerabilities CrackArmor security flaw
VulnerabilityAbout this happening: Researchers disclosed CrackArmor, nine confused deputy flaws in the Linux kernel's AppArmor module that can let unprivileged users bypass protections, gain root*...
Timeline
-
23.09.2026 14:12 1 articles · 3h ago
DepthFirst wins Google kernelCTF slot with AF_UNIX exploit
Technical Analysis UpdateDepthFirst won a Google kernelCTF slot on July 24 with an exploit for a Linux kernel AF_UNIX socket use-after-free later tracked as CVE-2026-80521, a flaw that can let a container escape and gain root on the host.
Show sources
- Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape — thehackernews.com — 23.09.2026 14:12
-
23.09.2026 14:12 1 articles · 3h ago
DepthFirst reports AF_UNIX use-after-free to kernel security team
Initial DisclosureDepthFirst reported the AF_UNIX socket use-after-free to the kernel security team on August 5 after its dfs-large1 model and a human-operated testing harness found the flaw in the Linux kernel.
Show sources
- Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape — thehackernews.com — 23.09.2026 14:12
-
23.09.2026 14:12 1 articles · 3h ago
Upstream Linux kernel fix lands for CVE-2026-80521
Mitigation Patch UpdateThe upstream Linux kernel fix for CVE-2026-80521 landed on August 6 in mainline kernel 7.2 and stable branch 7.1.10, while Ubuntu still had not shipped patches for 26.04, 24.04, or 22.04 LTS.
Show sources
- Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape — thehackernews.com — 23.09.2026 14:12
-
22.09.2026 03:00 2 articles · 1d ago
DepthFirst releases exploit code for Ubuntu 26.04
Technical Analysis UpdateDepthFirst published research on September 22 and released exploit code targeting Ubuntu 26.04 for CVE-2026-80521; Ubuntu 26.04, 24.04, and 22.04 LTS were still unpatched, and no temporary workaround had been published.
Show sources
- Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape — thehackernews.com — 23.09.2026 14:12
- Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape — thehackernews.com — 23.09.2026 14:12