
Attackers exploit CVE-2024-47756 in Ubuntu's AF_UNIX socket subsystem to escape containers and gain host root access through a kernel garbage collector race condition. The vulnerability bypasses namespace isolation and seccomp filtering, enabling lateral movement across container workloads. Runtime segmentation helps contain post-compromise activity. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/ubuntu-linux-cve-2026-80521-container-escape
