A person typing on a laptop computer. Photo by Štefan Štefančík on Unsplash. Source: https://unsplash.com/photos/person-wearing-long-sleeve-top-working-on-laptop-5p_7M5MP2Iw (Unsplash License).

A working Linux kernel container escape went public on September 22, and Ubuntu has not shipped the fix.

  • CVE-2026-80521 is a use-after-free in the kernel AF_UNIX socket cleanup, found with a model built for vulnerability detection. DepthFirst reported it to the kernel team on August 5.
  • It runs from an unprivileged process using default Docker or Kubernetes settings. No privileged container, no kernel module, no unusual flag.
  • Upstream fixed it on August 6. Ubuntu still lists 26.04 LTS and 24.04 LTS as vulnerable, and rates the issue Medium.
  • Kubernetes baseline pod security already allows the pieces the exploit needs, so cluster defaults are the exposure.
  • DepthFirst points to microVMs, where each workload carries its own kernel, as the durable fix.

Updating images does nothing. The bug lives in the shared host kernel. Read the full analysis.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.