Skip to finding
§
High
Privilege escalation
Confirmed
CVE-2026-80521

Public exploits let an ordinary process inside a current Ubuntu container take kernel control of the host.

Working code covers two unprivileged kernel races and includes test targets and a Docker harness.

Affects

Linux containers on Ubuntu 24.04 and 26.04 hosts sharing the host kernel.

What it enables

Container escape followed by kernel-level execution and root control of the host

Run as an ordinary user inside a container sharing the vulnerable host kernel.→↓Exercise the AF_UNIX descriptor-garbage-collection or reuseport cBPF race to produce a kernel use-after-free.→↓Use the released exploit's heap shaping and corrupted kernel object to obtain a kernel read/write primitive.→↓Escape the container and execute as root on the Ubuntu host.
Why this matters

Complete public exploits turn ordinary container-local execution into host-root execution across vulnerable Ubuntu estates.

Detail, proof-of-concept code and 6 sources
Required access

Code execution as an ordinary non-root process inside a Docker-style container on a vulnerable Ubuntu host.

Affected versions

Ubuntu 24.04 with Linux 6.8.0-139-generic, demonstrated for CVE-2026-52910, Ubuntu 26.04 with Linux 7.0.0-31-generic, demonstrated for CVE-2026-80521, Other kernel releases preceding the cited upstream stable fixes

Proof of concept

Public exploit code →

The two paths begin with unprivileged AF_UNIX/SCM_RIGHTS garbage collection or reuseport cBPF operations. Each produces a kernel use-after-free that the released heap-shaping code converts into a kernel read/write primitive.

From there, the exploit escapes the container and executes as root on the Ubuntu host. Fixes are published and revocation is complete, but pre-fix images remain accepted.

Evidence
DepthFirst published complete container-escape exploits and demonstrated them against current Ubuntu installations.Public source code includes test targets and a Docker harness.Upstream Linux records identify the defects and fixing commits.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026