Public exploits let an ordinary process inside a current Ubuntu container take kernel control of the host.
Working code covers two unprivileged kernel races and includes test targets and a Docker harness.
Linux containers on Ubuntu 24.04 and 26.04 hosts sharing the host kernel.
Container escape followed by kernel-level execution and root control of the host
Complete public exploits turn ordinary container-local execution into host-root execution across vulnerable Ubuntu estates.
Detail, proof-of-concept code and 6 sources
The two paths begin with unprivileged AF_UNIX/SCM_RIGHTS garbage collection or reuseport cBPF operations. Each produces a kernel use-after-free that the released heap-shaping code converts into a kernel read/write primitive.
From there, the exploit escapes the container and executes as root on the Ubuntu host. Fixes are published and revocation is complete, but pre-fix images remain accepted.
- access:local:unprivileged
- code running as an unprivileged local user
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Revocation complete
- Yes
- Reaches end-of-life hardware
- No