Public code now escapes an ordinary Ubuntu 26.04 container and gains root on its host through AF_UNIX.
Unprivileged container code is sufficient on the demonstrated target, and several current Ubuntu kernel packages were still listed as vulnerable on September 24.
Affects
The Linux kernel, including vulnerable Ubuntu kernels used by Docker and Kubernetes container hosts.
What it enables
Container escape to host root and kernel-level execution
Attacker runs as a non-root process inside a standard container on the demonstrated Ubuntu 26.04 host.→↓Concurrent AF_UNIX send and close operations expose an edge before its skb is queued.→↓Garbage collection partially frees a strongly connected component without unlinking its persistent scc_entry.→↓A later garbage-collection pass traverses the freed vertex, producing a heap use-after-free.→↓The published target-specific exploit converts the corruption into kernel execution, crosses the container namespaces and obtains host root.
Why this matters
A container workload can cross the host-kernel boundary without container privileges, and usable exploit code is public.
Detail, proof-of-concept code and 5 sources
Required access
Unprivileged code execution inside a container sharing the vulnerable host kernel
Affected versions
Linux 6.10 through 7.1.9, Linux stable branches containing the backport introduced at 6.1.141 or 6.6.93 without a corresponding fix, Ubuntu 26.04 kernel 7.0.0-31-generic, demonstrated, Ubuntu 24.04 and selected Ubuntu 22.04 HWE/cloud kernels listed vulnerable by Canonical on 2026-09-24
The chain starts with a concurrent AF_UNIX send-and-close race. It leaves a freed garbage-collector vertex linked into a persistent SCC ring, and a later collection pass traverses that freed object.
The published target-specific exploit converts that corruption into kernel execution and host root. Upstream fixes exist, but the Ubuntu package state made remediation incomplete as of September 24.
Evidence
DepthFirst reports a successful host-root escape against Ubuntu 26.04 and published the complete target-specific exploit.The public repository pins the demonstrated target to Ubuntu 26.04 kernel 7.0.0-31-generic.The upstream patch and Linux CVE announcement establish the AF_UNIX use-after-free and fixed releases.Canonical still listed multiple current Ubuntu kernel packages as vulnerable on 2026-09-24.
Preconditions
access:local:unprivileged
code running as an unprivileged local user
Patch reality
Reaches end-of-life hardware
No
The first two questions are not established by the available evidence; this is a host-kernel source fix, with no documented artifact rejection or revocation component.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.