NewsThe Hacker News2026-09-23 11:12 UTC
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
Linked advisories
- CVE-2026-80521af_unix: Unlink scc_entry in unix_del_edge().
- CVE-2026-80521Sicherheitsluecke -- CVE-2026-80521
- CVE-2026-80521Im Linux-Kernel wurde folgende Schwachstelle behoben: `af_unix`: Unlink `scc_entry` in `unix_del_edge()`.
- CVE-2026-80521Linux Kernel: Mehrere Schwachstellen
- CVE-2026-80521Debian linux: security update
More on Unpatched
Other advisories
- CVE-2025-59851lowHCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, whic…
- osv:CVE-2026-35667noneOpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.ts
- osv:ECHO-ddb8-c818-edcanoneVulnerable code is not present in libraw 0.21.4 (the version shipped in Debian trixie). The CVE describes a heap out-of-bounds write in HuffTable::initval (src/decompressors/losslessjpeg.cpp), reachable via LibRaw::sony_ycbcr_load_raw -> LibRaw_LjpegDecompressor::initialize -> HuffTable::initval. None of those symbols exist in 0.21.4: the src/decompressors/ directory, the LibRaw_LjpegDecompressor class, and the sony_ycbcr_load_raw entry point were all introduced together in libraw 0.22.0. Empirically confirmed by running the public PoC from https://github.com/biniamf/pocs/tree/main/libraw_lljpeg against an ASan build of unpatched libraw 0.21.4: the file is rejected at open with "Unsupported file format or not RAW file"; the same PoC reproduces the heap-buffer-overflow in 0.22.0 with the stack trace from the Talos report.
- CVE-2024-52798nonepath-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
- osv:CVE-2024-52798nonepath-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
- CVE-2024-44625noneUnpatched Remote Code Execution in Gogs in gogs.io/gogs
- CVE-2023-30549noneUnpatched extfs vulnerabilities are exploitable through suid-mode Apptainer in github.com/apptainer/apptainer
- CVE-2023-30549noneUnpatched extfs vulnerabilities are exploitable through suid-mode Apptainer
Other news entries
- Newsbleepingcomputer2026-10-09Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
- Newssecurityweek2026-10-09Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
- Newsthehackernews2026-10-07Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
- Newsthehackernews2026-10-01Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- Newsthehackernews2026-09-27Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Newsbleepingcomputer2026-09-25ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
- Newsthehackernews2026-09-24Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
- Newsbleepingcomputer2026-09-09Over 36,000 exposed Plex servers vulnerable to recent flaws
Source: https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html
ID