Container Escape, AWS at Home, and Audio Enhancements

Homelab Highlights for 2026-09-23: self-hosting and homelab notes worth knowing.

[Audio embed placeholder]

News Roundup

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two chained vulnerabilities in MikroTik RouterOS (CVE-2026-67279 and CVE-2026-86060) allow attackers to gain full administrative control of internet-exposed routers without authentication. The chain, dubbed MikroTrick, combines an SSH state-machine flaw with an argument-injection bug.

Why it matters: If you use MikroTik routers as your network edge and have SSH exposed, this is a high-priority patch. MikroTik released a fix in RouterOS version 7.17.

Source: The Hacker News

Plex Announcement - Audio Enhancements: Boost Dialog & Normalize Loudness

Plex has introduced two new audio features for Plex Pass subscribers: Boost Dialog isolates dialogue frequencies for clearer conversations, and Normalize Loudness keeps overall volume consistent using the EBU R128 standard. Both require audio transcoding and, notably, a Plex Pass on the user’s account, not just the server admin’s.

Why it matters: These are significant quality-of-life improvements for media playback, addressing common viewer complaints about inconsistent audio levels. The user-level subscription requirement is a key consideration for shared servers.

Source: r/PleX

Major Update to HA-arr-stack-card for Home Assistant

A developer has released a major update to the HA-arr-stack-card, a Home Assistant card for managing the ARR media stack (Radarr, Sonarr, Lidarr). New features include full Lidarr support with calendars, a similarity search for finding related media, Last.fm integration for music recommendations, a French language translation, and a performance refactor to load only necessary code.

Why it matters: This card consolidates management of popular self-hosted media tools into a single, performant Home Assistant interface, adding advanced discovery features and broadening support to include music libraries.

Source: GitHub

Filewright: A Windows Tool for Organizing Photos by Date Using Local AI

A developer shared their experience using Filewright, a Windows tool that organizes photos into dated folders. Testing on 639 personal photos revealed 23.8% had no usable EXIF or filename date. The tool uses a small local AI model as a last resort to guess dates from file timestamps, clearly labeling such guesses. It runs entirely offline.

Why it matters: For datahoarders with large, disorganized photo libraries, this tool offers a practical, privacy-preserving method to impose order, with transparency about the reliability of its date assignments.

Source: Microsoft Store

Tool & Software Highlight: Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

A use-after-free vulnerability (CVE-2026-80521) in the Linux kernel’s AF_UNIX socket subsystem can allow a container to escape and gain root access on the host. The upstream fix was released on August 6, but Ubuntu has not yet shipped patches for its 26.04, 24.04, or 22.04 LTS releases.

Why it matters: This is a critical security issue for any homelab running containers on affected Ubuntu LTS versions, especially services exposed to untrusted networks. The exploit requires no special container privileges to start and could hand over full control of the host system.

Source: The Hacker News

Sources

Transcript

Host A: Welcome to Homelab Highlights, the show that surfaces practical homelab wins and useful self-hosted tools.

Host A: DepthFirst security researchers have dropped an exploit for a Linux kernel bug that’s a container’s worst nightmare. [with emphasis] It’s a use-after-free in the AF_UNIX socket subsystem, tracked as CVE-2026-80521, and it can let a container escape to get root on the host.

Host B: The upstream kernel fix landed on August 6th, but according to the article, Ubuntu hasn’t shipped patches for its 26.04, 24.04, or 22.04 LTS releases yet. That’s a pretty wide-open window.

Host A: For a homelab, that means any containerized service—Docker, LXC, systemd-nspawn—could be a potential escape route if someone finds a way to trigger the bug. The exploit doesn’t need special container privileges to start, and if it works, it hands over the host root keys.

Host B: The practical takeaway is to check if you’re running those Ubuntu LTS versions with containers, especially on anything facing untrusted networks. The article doesn’t mention workarounds, so the main move is waiting for Canonical’s patches or, if it’s an option, considering a kernel from another source. It’s a solid reminder to watch your distro’s security advisories closely.

Host B: Next up, a nasty one for network gear. The Hacker News reports a vulnerability chain in MikroTik RouterOS that CERT Polska is calling MikroTrick. It combines an SSH state-machine flaw with an argument-injection bug, letting attackers take full admin control of internet-exposed routers without a password or SSH key.

Host A: That’s a bad day for anyone using MikroTik as their edge. MikroTik released a fix in version 7.17, so if you’re on an older version and have SSH open to the world, it’s definitely patching time. [thoughtful]

Host B: [lighter] On a completely different note, Plex announced two new audio features for Plex Pass subscribers. Boost Dialog tries to isolate dialogue frequencies to make quiet conversations clearer, and Normalize Loudness aims to keep overall volume levels consistent using the EBU R128 standard.

Host A: A welcome quality-of-life update for sure, especially if you’re tired of riding the remote. The catch, noted in the announcement, is that both features require a Plex Pass on the user’s account, not just the server admin’s. So if you share your server, your users need their own subscriptions to get the benefits.

Host B: Shifting to a community project, a developer posted a major update to the HA-arr-stack-card for Home Assistant. This card lets you manage the whole ARR stack—Radarr, Sonarr, and now Lidarr—right from the HA interface. The new version adds Lidarr support with calendars, a similarity search for finding related media, and Last.fm integration for music recommendations.

Host A: They also did a significant refactor so the card only loads the JavaScript for the features you actually use, which should help performance on slower phones and tablets. The developer mentions using AI to speed up development but is clear about reviewing and refactoring the code to avoid an unmaintainable mess.

Host B: And finally, a datahoarder shared their experience with a Windows tool called Filewright that organizes photos by date. They ran it on 639 personal photos and found nearly a quarter—23.8 percent—had no usable EXIF or filename date. The tool uses a small local AI model as a last resort to guess dates from file timestamps, with clear labels so guesses aren’t mistaken for facts. Everything runs offline, which is a nice touch.

Host A: For a deeper tool dive, let’s look at Spinifex. [thoughtful] It’s an open-source project from Mulga that reimplements the AWS API on your own hardware—EC2, S3, VPC, IAM, EKS, RDS, the whole suite. But it runs actual QEMU VMs and OVN networks, not just an API mock like LocalStack.

Host B: The pitch is pretty compelling for homelabs. If your day job involves AWS, or you’re studying for a certification, you can point your existing Terraform, CLI, and SDKs at your own rack instead of a cloud bill. The project’s engineers say it installs as a single-node cluster from a USB or ISO, and you can add more nodes later.

Host A: They’re upfront about what’s not fully baked yet. IAM compatibility is a work in progress—they implement 76 of the APIs, but policy versions and some condition operators aren’t there, which can trip up Terraform. The policy engine rejects anything it can’t enforce, so you won’t have silent security gaps. Under the hood, it uses NATS for the control plane, OVN for networking, and a custom object store for S3 and EBS, with data sharded across nodes. They mention GPU passthrough works for both EC2 and ECS, and they have Bedrock-compatible inference on the roadmap. For anyone who’s fought with OpenStack’s complexity but wants real cloud semantics, this looks like a fascinating alternative.

Host B: Wrapping up with a community highlight from the coding world. A developer posted about finally moving their development workflow off Claude Code and onto open-source models. [conversational]

Host A: The post says Claude Code, and Opus specifically, had been the default because it could handle not just tasks but also a lot of the surrounding cognitive load to make things work as expected.

Host B: But with newer OSS models like Kimi K3, GLM 5.3 Flash, and DeepSeek V4.1 Flash becoming available, the developer’s take was that model capability alone wasn’t worth putting up with the platform’s restrictions anymore. So they moved fully to using a service called Opencode for their coding assistance.

Host A: That’s Homelab Highlights for Wednesday. Until next time, happy hosting!