Container escape via IPv6 fragmentation bug in Linux kernel
Attack Techniques & Methods2026-07-01, 09:07
Researcher demonstrated PoC
IPV6_FRAG_ESCAPE exploiting a memory-handling flaw in Linux kernel 6.12.x (RHEL/CentOS 10). The vulnerability, now patched but without CVE ID, lets a process inside a container trigger memory corruption and escalate privileges to root on the host.The attack works in stages: first the improper memory access is triggered, then kernel protection mechanisms are bypassed, allowing the process to modify kernel settings and launch arbitrary code with root rights outside the container boundary.
Vendors
Products