cross-posted from: https://lemmy.world/post/52268026
A new Linux kernel vulnerability, CVE-2026-80521, affects the AF_UNIX socket subsystem and involves a race condition in the kernel’s socket garbage collector. The issue is rated CVSS 7.8 High, and research published this week demonstrated a container escape against affected Ubuntu kernels, potentially allowing an attacker to reach root on the host. The vulnerable AF_UNIX functionality is normally available to container workloads, making kernel isolation an important security boundary. The upstream fix is available, but Ubuntu’s security tracker currently lists affected releases with patch status still in progress. Ubuntu’s tracker lists 26.04 as vulnerable/work in progress and 24.04 as vulnerable


