Apply upstream kernel patch released August 6, 2026. Until Ubuntu releases a patched kernel for affected LTS versions, administrators should restrict container privileges, monitor official Ubuntu security advisories, and consider kernel recompilation from source if feasible. Limit AF_UNIX socket access within containers where possible.
Quick answers
What is CVE-2026-80521?
Apply upstream kernel patch released August 6, 2026. Until Ubuntu releases a patched kernel for affected LTS versions, administrators should restrict container privileges, monitor official Ubuntu security advisories, and consider kernel recompilation from source if feasible. Limit AF_UNIX socket access within containers where possible.
How severe is CVE-2026-80521?
high, CVSS 7.8
Is CVE-2026-80521 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-80521 be mitigated?
Apply upstream kernel patch released August 6, 2026. Until Ubuntu releases a patched kernel for affected LTS versions, administrators should restrict container privileges, monitor official Ubuntu security advisories, and consider kernel recompilation from source if feasible. Limit AF_UNIX socket access within containers where possible.
CVSS
7.8
Vendor
Ubuntu
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Ubuntu Linux 22.04 LTS, Ubuntu Linux 24.04 LTS, Ubuntu Linux 26.04 LTS
Mitigation
Apply upstream kernel patch released August 6, 2026. Until Ubuntu releases a patched kernel for affected LTS versions, administrators should restrict container privileges, monitor official Ubuntu security advisories, and consider kernel recompilation from source if feasible. Limit AF_UNIX socket access within containers where possible.
Security researcher DepthFirst has released exploit code for CVE-2026-80521, a use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem. The flaw, patched upstream on August 6, 2026, allows unauthenticated attackers to escape container isolation and gain root-level access on the host system. Ubuntu has not yet delivered the fix to its 22.04, 24.04, and 26.04 LTS releases, leaving users exposed despite the availability of an upstream kernel patch.