Tag
#Use-After-Free
CVE-2026-80521: Unpatched Ubuntu Linux Flaw Enables Host-Root Container Escape
A use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem, tracked as CVE-2026-80521 (CVSS score: 7.8), allows container escape and host root access. The flaw was patched upstream on August 6 but remains unpatched in Ubuntu 26.04, 24.04, and 22.04 LTS releases. An exploit has been released, but active exploitation has not been confirmed. Immediate patching or mitigation is recommended.
Critical Vulnerability in Suricata: CVE-2026-94084
A critical use-after-free vulnerability (CVE-2026-94084) has been discovered in Suricata versions before 8.0.7. This vulnerability can be exploited remotely, allowing attackers to potentially achieve high confidentiality, integrity, and low availability impacts. Security professionals should update Suricata to version 8.0.7 or later immediately.
Linux Kernel Vulnerability: CVE-2026-64530 - Use-After-Free in net/sched/cls_api.c
A use-after-free vulnerability was discovered in the Linux kernel's net/sched/cls_api.c, specifically in the tcf_qevent_handle function. This vulnerability can be exploited by an attacker to potentially execute arbitrary code or cause a denial-of-service (DoS) condition. Linux kernel versions 5.15.148, 6.1.75, 6.6.14, and 6.7.2 are affected.
Critical Use-After-Free Vulnerability in Zephyr's Dynamic Kernel-Object Tracking (CVE-2026-10667)
A critical use-after-free vulnerability (CVE-2026-10667) has been discovered in Zephyr's dynamic kernel-object tracking, affecting SMP systems with userspace enabled. This vulnerability allows a deprivileged user thread to corrupt kernel object-tracking structures, potentially leading to privilege escalation or denial of service. The vulnerability has a CVSS score of 7.8 and affects Zephyr versions from 1.14.0 to 4.4.0. Immediate patching is recommended to prevent potential exploitation.