• Sources: primary, exploit, advisory, discussion
  • Summary: NVD published CVE-2026-53361 on 2026-07-04 at CVSS 7.1 from the kernel.org CNA. NVD describes a race condition in AF_UNIX garbage collection, where unix_gc() could run with gc_in_progress false when work is scheduled while it is already running and unix_peek_fpl() relies on that flag, and records the fix as setting gc_in_progress to true in unix_gc(). The CNA vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H records local access and low privileges as required and no confidentiality impact, with fixes in 6.6.144, 6.12.95, 6.18.38, and 7.1, and Debian DSA-6381-1 records 6.12.95-1 for trixie. A public repository now carries exploit code, and the container escape, the use-after-free framing, and the claim that Ubuntu 24.04 HWE 6.17 and RHEL 10 remain unpatched are the exploit author's alone and were not verified for this digest.
  • Why it matters: Anyone running untrusted or multi-tenant containers on an unpatched 6.12, 6.17, or 6.18 kernel now faces public exploit code rather than a patch note, and the fixed stable versions are the check to run.
  • Follow-up: Whether distributions confirm or refute the unpatched claims for Ubuntu 24.04 HWE and RHEL 10.

send feedback on this story