Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
bad_garbage — CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape | Kitploit
Tools/GitHubGitHub/sgkdev/bad_garbage
Container SecurityVulnerability AnalysisExploitationContainer EscapeBinary Exploitation
GitHubsgkdev/bad_garbage

bad_garbage

CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

View Repository
256271 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

BAD_GARBAGE.c

CVE-2026-53361 — an unprivileged, container-escapable use-after-free in the AF_UNIX socket garbage collector. This is the single-vector (MSG_PEEK only) version.

The Bug

The AF_UNIX GC reclaims "in-flight" sockets that form unreachable reference cycles. A concurrent MSG_PEEK on an in-flight fd takes a reference the GC's census never counts, so the collector can free a socket that is still alive and leave a dangling sk_buff. The peek is supposed to back off while a collection runs, but the gc_in_progress flag it checks can read false mid-run, so the peek slips through and the race is open.

Same interaction, fixed three times:

  • CVE-2021-0920 — cbcf01128d0a "af_unix: fix garbage collect vs MSG_PEEK"
  • CVE-2026-23394 — e5b31d988a41 "af_unix: Give up GC if MSG_PEEK intervened"
  • CVE-2026-53361 — d82ba05263c6 "af_unix: Set gc_in_progress to true in unix_gc()"

Targets

Vulnerable = affected by the bug. Targeted = covered by this exploit (single MSG_PEEK vector). The 7.x kernels and the Ubuntu 6.8 GA kernel are vulnerable but out of scope here.

TargetKernelVulnerablePatchedTargeted
Stable 6.126.12Y6.12.95up to 6.12.94
Ubuntu 24.04 HWE6.17YNup to 6.17.0-41
Ubuntu 24.04 GA6.8YNN (non-PEEK vector)
RHEL 106.12YNY
Debian trixie6.12YDSA-6381-1up to 6.12.94+deb13-cloud-amd64

A Few Kernels Tested

LineLatest tested kernelBuild date
Debian 13 (trixie)6.12.94+deb13-cloud-amd64Jun 20, 2026
Ubuntu 24.04 (6.17)6.17.0-41-genericJun 30, 2026
Ubuntu 24.04 (6.14)6.14.0-37-genericNov 20, 2025 (old HWE)
CentOS Stream 106.12.0-257.el10Aug 6, 2026 13:25 GMT
RHEL 10.2 / AlmaLinux6.12.0-211.43.1.el10_2Aug 6, 2026 17:19 GMT

Notes

  • CPU count — designed for fewer than 8 CPUs (2–7). A choice, not a reliability quirk: the clean order-N strategy is left out on purpose, not worth exposing it for a -1 day bug.
  • SLUB Cache Armoring — most cache-armoring/shadowing code was stripped from the PoC. The SID-leak phase can occasionally collide with a spurious low-order kmalloc() or a specific per-cache PCP reuse (anon_vma, kmalloc-64, and friends); the higher buckets are safe, the dedicated caches and lower buckets are not. Add your own armoring to push it toward ~100%.
Download Tool