DigiNews

Tech Watch by Johan Denoyer

← Back to articles

BAD_GARBAGE.c: The AF_UNIX Container Escape That Resurrected Twice - Part I

Quality: 8/10 Relevance: 9/10

Summary

The article analyzes a Linux AF_UNIX container escape vulnerability chain, tracking CVEs 2021-0920, 2026-23394, and 2026-53361, and explains how a 2024 Tarjan SCC-based garbage collection rewrite impacted the exploit. It discusses affected kernel versions across major distributions (Ubuntu, RHEL, Debian), SELinux implications, and provides context on mitigation and patch timelines for defenders and operators of containerized environments.

🚀 Service construit par Johan Denoyer