High

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

The Hacker News

Overview

A recently discovered flaw in the Linux kernel's AF_UNIX socket subsystem poses a significant risk to Ubuntu users running versions 22.04, 24.04, and 26.04 LTS. The vulnerability, identified as CVE-2026-80521, allows attackers to escape from a container environment and gain root access to the host system. Although the issue was patched upstream on August 6, the fixes have not yet been implemented in the affected Ubuntu releases. This situation creates a window of opportunity for potential exploitation, which could lead to serious security breaches for users running these versions. Organizations relying on these Ubuntu LTS releases should take immediate action to safeguard their systems.

Key Takeaways

  • Affected Systems: Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 26.04 LTS
  • Action Required: Users of affected Ubuntu LTS versions should apply the upstream patch released on August 6, 2023.
  • Timeline: Disclosed on September 22, 2023

Original Article Summary

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst

Impact

Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 26.04 LTS

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on September 22, 2023

Remediation

Users of affected Ubuntu LTS versions should apply the upstream patch released on August 6, 2023. Regularly check for updates from Ubuntu to ensure that the patch is included in their releases. Until the official patch is available, consider isolating containers or applying additional security measures to mitigate risks.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Linux, CVE, Exploit, and 3 more.

Related Coverage

Hackers start exploiting critical WordPress flaw for code execution

BleepingComputer

A critical vulnerability in WordPress, identified as CVE-2026-87902, is currently being exploited by hackers. Initially, attackers were probing for sites that were vulnerable, but they have now escalated to exploiting the flaw to write files to disk that can execute shell commands when accessed. This puts numerous WordPress installations at risk, particularly those running outdated or unpatched versions of the software. Users and website administrators need to take this threat seriously, as the exploitation can lead to unauthorized access and control over affected sites. This situation underscores the importance of timely updates and security measures in maintaining website integrity.

Sep 23, 2026

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker News

Researchers have identified a serious vulnerability affecting MikroTik routers that allows attackers to gain full administrative control without needing a password or SSH key. Known as the MikroTrick chain, this issue arises from two flaws in the RouterOS software: an SSH state-machine vulnerability (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060). These vulnerabilities can be exploited on routers that are exposed to the internet, putting numerous devices at risk. Users of MikroTik routers should take immediate action to secure their devices, as the potential for unauthorized access could lead to significant data breaches or network disruptions.

Sep 23, 2026

UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

darkreading

In the first half of 2026, the United Arab Emirates and Saudi Arabia faced a significant increase in cyberattacks, accounting for half of all incidents reported in the Gulf region. These attacks have become more complex, posing serious challenges for cybersecurity teams in both countries. The rise in incidents affects various sectors, raising concerns about the security of sensitive data and critical infrastructure. This situation highlights the urgent need for enhanced cybersecurity measures and collaboration among nations to combat these evolving threats. The implications of these attacks could be far-reaching, affecting not only businesses but also national security and public trust in digital systems.

Sep 23, 2026

How One Kubernetes YAML Can Hand Over a GCP Organization

BleepingComputer

A recent security analysis reveals that a Kubernetes user with limited permissions can exploit a flaw in Google Kubernetes Config Connector to gain control over an entire Google Cloud organization. This issue stems from a confused deputy problem, where the permissions granted to the Config Connector can be misused through a single Kubernetes YAML file. This vulnerability poses a significant risk because it allows unauthorized users to escalate their privileges and potentially compromise sensitive resources across the organization. Organizations using Google Cloud and Kubernetes need to be aware of this risk and take measures to secure their configurations. The implications of such a breach could be severe, affecting data integrity and access control.

Sep 23, 2026

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News

Threat actors have compromised two legitimate MemTensor packages on the npm and PyPI repositories to distribute a malicious program called sckit. This implant targets Windows, Linux, and macOS systems and is designed to steal credentials. Researchers from Aikido, SafeDep, Socket, and StepSecurity have reported on the affected libraries, particularly the @memtensor/memos-cloud-openclaw-plugin versions. This incident raises significant security concerns for developers and users who may have unknowingly installed these compromised packages. It's crucial for affected users to take immediate action to safeguard their systems.

Sep 23, 2026

Arista patches actively exploited VeloCloud Orchestrator zero-day

BleepingComputer

Arista Networks has addressed a zero-day vulnerability in the VeloCloud Orchestrator (VCO) On-Prem deployments, which is currently being exploited by attackers. This flaw poses a significant risk, as it allows unauthorized access to the system, potentially compromising sensitive data and network operations. Users of the VCO should apply the security patches released by Arista immediately to protect their systems. The urgency of this patching process is underscored by the fact that the vulnerability is actively being exploited in the wild. Organizations relying on VeloCloud Orchestrator must prioritize this update to mitigate the risk of an attack and safeguard their network infrastructure.

Sep 23, 2026