A working Linux kernel container escape went public on September 22, and Ubuntu has not shipped the fix.
- CVE-2026-80521 is a use-after-free in the kernel AF_UNIX socket cleanup, found with a model built for vulnerability detection. DepthFirst reported it to the kernel team on August 5.
- It runs from an unprivileged process using default Docker or Kubernetes settings. No privileged container, no kernel module, no unusual flag.
- Upstream fixed it on August 6. Ubuntu still lists 26.04 LTS and 24.04 LTS as vulnerable, and rates the issue Medium.
- Kubernetes baseline pod security already allows the pieces the exploit needs, so cluster defaults are the exposure.
- DepthFirst points to microVMs, where each workload carries its own kernel, as the durable fix.
Updating images does nothing. The bug lives in the shared host kernel. Read the full analysis.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
