BadGarbage (CVE-2026-53361) Local Root and Container Escape

Incident Report for CloudLinux

Identified

Summary

BadGarbage (CVE-2026-53361, CVSS 7.0) is a vulnerability tied to a race condition in the Linux kernel’s Unix-socket garbage collector. Any local user, including a process inside a container, can exploit the flaw to become root on the host. A public working proof-of-concept exists.

Affected Platforms

CloudLinux 10.

Mitigation

None at runtime; the fix is a patched kernel or a KernelCare livepatch.

Current Status

- Patched Kernel:
The fix for BadGarbage comes from AlmaLinux’s patched kernel "6.12.0-211.47.1.el10_2", which is available in the stable repository. To update, run:
dnf update 'kernel*'
reboot

- KernelCare
The KernelCare livepatch for CVE-2026-53361 is in preparation.
Posted Aug 18, 2026 - 22:03 UTC
This incident affects: CloudLinux OS Components (CloudLinux Kernel).