important2 findings, 19 signals7 min read

Public code crossed an ordinary Ubuntu container into host root, and a no-permission OxygenOS app reached root through preinstalled services.

Container namespaces and Android’s application sandbox each became paths to more privileged execution.

Priority findings2
01
High
Privilege — Containers
Confirmed
CVE-2026-80521

Public code now escapes an ordinary Ubuntu 26.04 container and gains root on its host through AF_UNIX.

Unprivileged container code is sufficient on the demonstrated target, and several current Ubuntu kernel packages were still listed as vulnerable on September 24.

Affects

The Linux kernel, including vulnerable Ubuntu kernels used by Docker and Kubernetes container hosts.

What it enables

Container escape to host root and kernel-level execution

Attacker runs as a non-root process inside a standard container on the demonstrated Ubuntu 26.04 host.→↓Concurrent AF_UNIX send and close operations expose an edge before its skb is queued.→↓Garbage collection partially frees a strongly connected component without unlinking its persistent scc_entry.→↓A later garbage-collection pass traverses the freed vertex, producing a heap use-after-free.→↓The published target-specific exploit converts the corruption into kernel execution, crosses the container namespaces and obtains host root.
Why this matters

A container workload can cross the host-kernel boundary without container privileges, and usable exploit code is public.

Detail, proof-of-concept code and 5 sources
Required access

Unprivileged code execution inside a container sharing the vulnerable host kernel

Affected versions

Linux 6.10 through 7.1.9, Linux stable branches containing the backport introduced at 6.1.141 or 6.6.93 without a corresponding fix, Ubuntu 26.04 kernel 7.0.0-31-generic, demonstrated, Ubuntu 24.04 and selected Ubuntu 22.04 HWE/cloud kernels listed vulnerable by Canonical on 2026-09-24

Proof of concept

Public exploit code →

The chain starts with a concurrent AF_UNIX send-and-close race. It leaves a freed garbage-collector vertex linked into a persistent SCC ring, and a later collection pass traverses that freed object.

The published target-specific exploit converts that corruption into kernel execution and host root. Upstream fixes exist, but the Ubuntu package state made remediation incomplete as of September 24.

Evidence
DepthFirst reports a successful host-root escape against Ubuntu 26.04 and published the complete target-specific exploit.The public repository pins the demonstrated target to Ubuntu 26.04 kernel 7.0.0-31-generic.The upstream patch and Linux CVE announcement establish the AF_UNIX use-after-free and fixed releases.Canonical still listed multiple current Ubuntu kernel packages as vulnerable on 2026-09-24.
Share this finding
02
High
Mobile — Privilege
Confirmed

A no-permission OxygenOS app can chain two vendor services into full root execution.

The same APK worked on stock OnePlus 15 and OnePlus 12 Pro devices; OnePlus says additional OnePlus and OPPO products are affected.

Affects

OnePlus OxygenOS, the vendor Android distribution on OnePlus phones; OnePlus says related OPPO products are also affected.

What it enables

Root command execution from an ordinary Android application

Attacker gets a plain no-permission APK running in the Android untrusted_app domain.→↓The APK calls AtlasService.setEvent with the audio-dumpsys event and attacker-controlled property value.→↓audioDumpInfo runs as UID 0 in the dumpstate domain and interpolates that value into system(), producing a restricted root shell.→↓The root dumpstate process calls the olc2 HAL doShell method, whose only caller check is UID 0.→↓The HAL executes the supplied command in vendor_qti_init_shell with all Linux capabilities.
Why this matters

The chain starts in Android’s ordinary untrusted_app domain with no requested permissions and ends in a vendor shell with all Linux capabilities.

Detail and 2 sources
Required access

Execution as a normal installed Android app with no requested permissions

Affected versions

OnePlus 15 CPH2747 running OxygenOS 16.0.3.503, security patch level 2026-02-01, OnePlus 12 Pro CPH2581, software version not stated

Proof of concept

Demonstrated by the researcher

An unrestricted AtlasService Binder call places attacker-controlled text into audioDumpInfo, which interpolates it into system() while running as UID 0. That first step provides a restricted root process in the dumpstate domain.

The process can then call olc2 doShell, whose only caller check is UID 0, and execute commands in vendor_qti_init_shell with all capabilities. OnePlus announced remediation, but it did not publish a complete affected-product list.

Evidence
The researcher ran the same no-permission APK successfully on stock OnePlus 15 and OnePlus 12 Pro devices.The published analysis traces both Binder calls, the command injection and the resulting UID and capability context.OnePlus confirmed broader OnePlus and OPPO exposure but did not publish the complete affected list.
Share this finding
Signals19
important · Firmware — Physical

Dell BOSS-N1 firmware can persist while iDRAC verifies a clean inactive image.

Affects

Dell 17G Boot Optimized Server Storage N-1 controllers used as operating-system boot storage in PowerEdge and related servers.

Physical bus access, or equivalent access after an iDRAC compromise, reaches unauthenticated S-MCU debugging and update paths. Modified firmware can then redirect verification reads to the unchanged slot.

Detail and 3 sources
important · Edge — Developer tools

A repository owner could replace a SHA-pinned Codex plugin during automatic update and execute code on the developer host.

Affects

Codex CLI, a local AI coding agent and plugin client on developer workstations.

A branch named after the reviewed commit could win Git’s ambiguous-ref resolution because the updater did not check the resulting HEAD. The replacement plugin then ran with the Codex user’s local and connected access.

Detail and 2 sources
important · Mobile — Local storage

Secure Folder kept imported PIN-protected files unencrypted in Android shared storage.

Affects

Secure Folder by FluteCode, a password-protected file-vault application for Android.

A local application with broad shared-storage access, or a person using a capable file manager, can read the originals under Documents/.SecureFolder without entering the PIN.

Detail and 2 sources
important · Edge — GitLab

One GitLab issue-by-email address can become account-wide repository and CI authority.

Affects

GitLab.com and GitLab Self-Managed source-code hosting and CI/CD installations with incoming email enabled.

The address embeds a non-expiring account-wide token. Changing its suffix to the merge-request route and attaching a patch can create commits as the owner, modify CI and operate outside project IP restrictions.

Detail and 3 sources
important · Edge — BIG-IP

Attackers are exploiting a pre-authentication header overflow for code execution on configured F5 BIG-IP APM gateways.

Affects

F5 BIG-IP Access Policy Manager, an application-delivery and remote-access appliance deployed at enterprise network edges.

Only virtual servers combining an APM policy with an OAuth authorization-server profile expose the path. An oversized Bearer header can corrupt an adjacent callback and reach command execution through a ROP chain and the tmm.finish hook.

Detail and 2 sources
important · RCE — VPN

Check Point says attackers are exploiting its pre-authentication VPN certificate RCE against Spark gateways.

Affects

Check Point Security Gateway and Spark Firewall, embedded network-security appliances providing firewall and VPN services.

Malicious certificate data supplied during VPN negotiation can execute code before authentication in the gateway service context.

Detail and 1 source
important · Physical — Access control

Brief NFC proximity to a Norwegian Cruise Line keycard can yield a lasting duplicate door credential.

Affects

Norwegian Cruise Line shipboard door-access controllers using NTAG212 NFC keycards.

The reader authenticates only the card’s cleartext seven-byte UID, with no cryptographic challenge-response. Reading range is approximately 2–5 centimeters, and the duplicate still must be presented at the protected door.

Detail and 1 source
important · Zero-click — Webmail

Attackers are exploiting Roundcube’s pre-authentication SQL injection.

Affects

Roundcube Webmail, a self-hosted browser-based email client commonly deployed on Linux hosting servers.

The exposed population is limited to installations using the optional virtuser_query plugin. There, a backslash-escape bypass lets login input reach SQL before authentication, enabling database commands, authentication bypass or access to Roundcube records.

Detail and 4 sources
important · RCE — WSO2

WSO2 confirms a JWT authentication bypass, while CISA describes the same CVE as an exploited upload-to-RCE flaw.

Affects

WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway, Java-based API-management and gateway services.

WSO2’s account says an unsupported signing algorithm can yield administrative account takeover. CISA’s account instead names path traversal, unrestricted upload and remote code execution.

Detail and 2 sources

We do not know whether the CVE conflates two vulnerabilities or how the asserted upload path relates to the JWT flaw.

important · Firmware — ViewBoard

A shared-network attacker can silently install and run an APK on ViewSonic ViewBoards.

Affects

ViewSonic ViewBoard Android smart displays running the vCast/EShare wireless-presentation service.

The unauthenticated vCast control socket accepts an attacker-selected APK URL and key-event commands that approve the Android installation prompts.

Detail and 2 sources
important · Privilege — Windows

Rapid7 assessment content could turn a writable Windows PATH entry into SYSTEM execution.

Affects

Rapid7 Insight Agent on Windows, an endpoint agent that runs centrally delivered InsightVM assessment content.

The attacker first needs a non-administrator-writable machine PATH directory ahead of Visual Studio Code. A planted executable named code is then selected by a SYSTEM assessment check.

Detail and 2 sources
important · Boot chain — Versal

Board-level access can turn Versal’s internal USB boot mode into arbitrary preboot execution.

Affects

AMD Versal Prime, Premium, AI Edge, AI Core, HBM, and RF adaptive SoCs, including specified Versal Premium Gen 2 devices used in embedded systems.

After non-trivial board modification exposes the test-only mode, a crafted USB image can overflow a buffer and replace an active function pointer.

Detail and 2 sources
important · Mobile — Physical control

Any authenticated iSteamX user could monitor and control other customers’ steam generators.

Affects

MrSteam iSteamX, a mobile application and connected hub used to monitor and control residential steam generators.

An overbroad AWS policy exposed wildcard MQTT topics for other customers’ telemetry and start-or-stop commands.

Detail and 2 sources
important · Boot chain — Zynq

A malicious USB host can overflow enabled Zynq UltraScale+ USB boot into first-stage-loader memory.

Affects

AMD Zynq UltraScale+ MPSoCs, Zynq UltraScale+ RFSoCs, and Kria system-on-modules using the optional USB boot implementation.

The route is limited to builds that include and enable USB boot. Excessive DFU download requests then overflow the DDR receive buffer into FSBL memory.

Detail and 2 sources

Unauthorized preboot execution remains potential; controlled instruction flow has not been demonstrated in the available record.

important · Zero-click — Identity

A forged JWT can impersonate a Cloudflare service token in nimble_zta 0.1.2.

Affects

nimble_zta, an Elixir authentication library used by Phoenix and Plug server applications behind Cloudflare Zero Trust.

The library discarded JOSE’s signature-verification verdict and returned decoded claims even after verification failed.

Detail and 2 sources
important · Firmware — Bluetooth

Botslab’s BLE, session and update flaws form a provisional path to modified G980H firmware.

Affects

Botslab G980H dash cameras, embedded recording devices with BLE provisioning, a local Wi-Fi network, HTTP services, and network-delivered firmware updates.

Unauthenticated BLE exposes protected Wi-Fi material; firmware-wide constants can recover it; session weaknesses expose privileged functions; and the updater lacks trusted-signature verification.

Detail and 4 sources
important · Wi-Fi — Research

A malformed 802.11 packet can terminate a live Wireshark process.

Affects

Wireshark, a cross-platform network protocol analyzer used for live packet capture and trace-file analysis.

The vendor considers over-the-wire triggering possible, but reliable radio injection into the crashing path has not been established.

Detail and 2 sources
important · Edge — CI supply chain

Re-enabling two compromised GitHub Actions restored malicious mutable tags and re-exposed thousands of downstream repositories.

Affects

GitHub Actions, the hosted and self-hosted CI workflow system used by GitHub repositories.

Disabling the compromised repositories had interrupted downstream execution. Re-enabling them without repairing the tags restored automatic payload delivery when scheduled or event-triggered workflows ran.

Detail and 1 source

The accessible record says two actions and thousands of repositories were involved, but we do not know the repository names, tag hashes, exact count or whether executions were observed after re-enablement.

Chain to watch
A GitHub Actions repository is compromised and a commonly referenced release tag is moved to malicious code.→↓GitHub disables the compromised action, interrupting downstream execution.→↓The action is later re-enabled without removing or repairing the malicious tag.→↓A downstream repository still referencing the mutable tag starts its next scheduled or event-triggered workflow.→↓The runner downloads and executes the malicious action in its CI context.→↓The exact action repositories, affected tag hashes, downstream count and post-reenable executions are not confirmed from the available record.
Unverified chainRetrieve Socket’s full September 24 report and compare the named repositories’ tag and workflow histories before and after re-enablement.
Also noted0

No additional findings today.

What was checked · 2 quiet
BluetoothQuiet

Unauthenticated Botslab BLE access exposes protected Wi-Fi credential material.

ResearchQuiet

AF_UNIX container escape, autonomous portal intrusion and BOSS-N1 verification bypass.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 25, 2026