SECURITY·중요도 8·2026. 09. 23.·The Hacker News
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
── KO ──────────────────
우분투 리눅스 플래가 호스트 루트로 탈출할 수 있는 취약점이 발견됐다.
리눅스 커널의 AF_UNIX 소켓 서브시스템에서 발견된 use-after-free 취약점이 컨테이너에서 탈출하여 호스트의 루트 권한을 획득할 수 있다고 보안 업체 DepthFirst가 발표했다. 이 취약점은 CVE-2026-80521로 추적되며, CVSS 점수는 7.8이다. 8월 6일에 패치가 발표되었지만, 우분투는 26.04, 24.04, 22.04 LTS 릴리스에 대해 아직 패치를 배포하지 않았다.
── EN ──────────────────
A vulnerability in Ubuntu Linux allows container escape to gain host root access.
A use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem can allow an escape from a container to gain root access on the host, according to research by the security firm DepthFirst. The flaw is tracked as CVE-2026-80521 and has a CVSS score of 7.8. It was patched upstream on August 6, but Ubuntu has not yet shipped the fix for its 26.04, 24.04, or 22.04 LTS releases.