Ubuntu reportedly had not distributed an official fix for affected releases as of September 27, 2026. In a technical disclosure published September 22, DepthFirst said it demonstrated a container escape involving CVE-2026-80521 on Ubuntu 26.04. The flaw is in the Linux kernel, so updating container software alone does not correct it.
What CVE-2026-80521 does
Canonical identifies CVE-2026-80521 as a use-after-free in the Linux kernel’s AF_UNIX socket garbage-collection code. A use-after-free occurs when software accesses memory after it has been freed, potentially allowing that memory to be misused.
Canonical assigns the vulnerability a CVSS 3 score of 7.8, High. Its separate Ubuntu priority rating is Medium; the two labels are distinct classifications.
Containers share the host’s Linux kernel. A flaw in that shared layer can therefore undermine the boundary between a container and its host, though the reported demonstration does not establish that every container configuration is exploitable.
How the kernel flaw occurs
The bug involves garbage collection of AF_UNIX socket messages that use SCM_RIGHTS. In DepthFirst’s technical account, the kernel makes a new socket-graph edge visible before queueing the associated socket buffer. A concurrent garbage-collection pass can then free a graph vertex without unlinking it from a persistent strongly connected component (SCC) ring. A later pass may follow the stale reference and access the freed memory.
Canonical describes the correction as af_unix: Unlink scc_entry in unix_del_edge(): the change unlinks the entry during the relevant operation.
Ubuntu kernel packages listed as vulnerable
Canonical’s CVE record, last updated September 24, 2026, gives package-specific assessments. The release name alone does not determine the status of every kernel package.
| Ubuntu release | Kernel package | Assessment in Canonical’s record |
| 26.04 LTS | linux | Vulnerable; work in progress |
| 24.04 LTS | linux | Vulnerable |
| 22.04 LTS | linux | Not affected |
| 22.04 LTS | linux-hwe-6.8 | Vulnerable |
| 22.04 LTS | linux-aws-6.8 | Vulnerable |
| 22.04 LTS | linux-azure-6.8 | Vulnerable |
| 24.04 LTS | linux-hwe-6.17, linux-hwe-7.0 | Vulnerable |
Canonical also lists vulnerable cloud and FIPS kernel variants in applicable Ubuntu 24.04 and 26.04 package rows. For Ubuntu 22.04, its base linux-aws and linux-azure packages are listed as not affected, while the named 6.8 variants are vulnerable.
What the reported demonstration covered
DepthFirst says its CVE-2026-80521 exploit escaped a container running on an unmodified Ubuntu 26.04 kernel. Its Ubuntu 24.04 demonstration concerns CVE-2026-52910, a separate vulnerability—not CVE-2026-80521. Canonical’s package record independently lists selected Ubuntu 24.04 kernel packages as vulnerable to CVE-2026-80521.
DepthFirst dates the upstream kernel patch to August 6, 2026. That upstream correction is distinct from Ubuntu’s distribution of fixed packages; the dated Ubuntu package assessments above are from Canonical’s September 24 record.
Why updating Docker is not enough
The vulnerability is in the host Linux kernel, not in Docker, runc, or containerd. Updating those runtime components alone does not put a kernel correction into the running host kernel.