CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape
A critical use-after-free vulnerability, CVE-2026-53361, has been identified in the Linux kernel's AF_UNIX socket garbage collector. The flaw allows unprivileged users to escape containers by exploiting a race condition during MSG_PEEK operations.
Why it matters
This vulnerability poses a significant security risk to cloud infrastructure and containerized environments, potentially allowing attackers to break out of isolated sandboxes.
CVE-2026-53361 — an unprivileged, container-escapable use-after-free in the AF_UNIX socket garbage collector. This is the single-vector (MSG_PEEK only) version.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in