PoC for CVE-2026-80521 Is Public; Ubuntu Fixes Underway for Some Packages
Researchers at DepthFirst published exploit source code for a Linux kernel flaw. Canonical still lists the vulnerability as unfixed for some Ubuntu packages.

CVE-2026-80521 Ubuntu is a security issue for which DepthFirst published research and a link to the exploit source code on September 22, 2026. It is a use-after-free flaw in the AF_UNIX socket garbage collector in the Linux kernel. Canonical still lists the linux package for Ubuntu 26.04 LTS as “Vulnerable, work in progress.”
The flaw is not remotely exploitable on its own. An attacker needs local access to a system with a vulnerable kernel, or the ability to run their own code in a container. The publicly available PoC therefore increases the importance of quickly checking the kernel packages in use, especially on hosts running untrusted containers.
CVE-2026-80521 Ubuntu: A flaw in AF_UNIX
AF_UNIX is a Linux kernel mechanism for local interprocess communication through Unix sockets. The vulnerability is located in its garbage collector, which handles object deallocation. A use-after-free flaw occurs when a program continues working with a reference to an object that is no longer valid after its memory has been freed.
The upstream kernel fix was incorporated on August 6, 2026. The fix is identified as “af_unix: Unlink scc_entry in unix_del_edge().” However, this does not automatically mean that the fix is already available in all Ubuntu distribution packages and images.
Ubuntu Security Tracker rates the vulnerability at CVSS 7.8. For the standard linux package for Ubuntu 26.04 LTS, it states that the system is vulnerable and that work on a fix is in progress. Available data also shows that the assessment cannot be simplified to the Ubuntu release name alone: the specific kernel package in use is decisive.
Jammy Is Not Vulnerable in All Configurations
The claim that all Ubuntu 22.04 LTS installations are affected is not accurate. Canonical marks the standard linux package for Jammy as “Not affected.” However, some cloud kernel packages with kernel 6.8 for this release are listed as vulnerable by the tracker. These include linux-aws, linux-azure, and linux-gcp.
Administrators should therefore verify the exact kernel package in use on the virtual machine, cloud image, or container host. The distribution version alone may not be sufficient to determine the status. Particular attention is warranted in environments using cloud kernels for which Canonical still lists the vulnerability.
PoC Suggests a Risk to Container Isolation
DepthFirst describes the exploit in the context of containers. Although containers separate processes and environments, they share the kernel with the host system. A kernel flaw may be relevant when an attacker has already gained the ability to execute code in a container or has a local account on a vulnerable system.
The researchers claim that their PoC could lead to container escape and the acquisition of root privileges on the host. However, this capability was not independently reproduced for every type of container deployment in the sources used. Likewise, there is no confirmed evidence that CVE-2026-80521 has been exploited in real-world attacks.
The practical significance of the published code is mainly that the vulnerability is no longer merely a theoretical entry in a security tracker. Organizations should identify systems with affected kernels, prioritizing hosts running untrusted containers and cloud instances with packages marked as vulnerable.
What to Watch Next
The confirmed solution is to deploy a fixed kernel version once it becomes available. The available information does not indicate a specific universal temporary mitigation from Canonical for all affected packages.
Further developments will include the release of an Ubuntu Security Notice and fixed versions of the kernel packages. Changes in the tracker status for Ubuntu 26.04, 24.04, and individual cloud packages will also be relevant, as will independent verification of the public PoC’s functionality or any reports of exploitation in practice.
Sources
- DepthFirst – The company reports the publication of the research, the existence of the exploit, and its focus on CVE-2026-80521.
- Ubuntu Security – Canonical confirms the flaw description, CVSS score, fix status, and differences between Ubuntu packages and releases.
- Linux kernel commit mirror – Records the upstream fix “af_unix: Unlink scc_entry in unix_del_edge()” incorporated on August 6, 2026.
- The Hacker News – Provides secondary corroboration of the PoC’s publication and states that attacks in practice have not been confirmed.
Verified and updated: September 23, 2026 15:27



