https://reddit.com/r/netsec/comments/1woiusv/september_23_24h_recap_ubuntu_container_escape_f5/: September 23 | 24h Recap: Ubuntu container escape, F5 OAuth RCE and Windows process injection
Published Sep 23, 2026
·Updated
Affected Software
3 affected components
Ubuntu Ubuntu=26.04
F5 BIG-IP APM
Microsoft Windows
Frequently Asked Questions
1
What access is needed to exploit the Ubuntu issue?
The exploit reaches host root from a container on Ubuntu 26.04, so an attacker would need execution from within a container. Affected distribution kernels still require the patch even though the AF_UNIX flaw was fixed upstream.
2
Is the F5 issue limited to the management interface?
No. Exploitation against vulnerable OAuth authorization-server configurations does not require management-interface access, and the issue is being exploited.
3
What remediation is available for the F5 issue?
Hotfixes are available for the F5 BIG-IP APM issue.
4
What does the Windows testing indicate about detection?
In Flashpoint's lab, the process-initialization-structure injection technique produced no alerts from the EDR controls tested. The technique avoids common memory-writing APIs.