Ancient Linux SCTP bug lets local attackers gain root and escape containers

TL;DR Summary
A long-standing use-after-free in Linux SCTP (CVE-2026-64564, nicknamed SCTPhantom) can allow a local user to gain root on a host and escape containers when SCTP is reachable; patches landed in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148 as of August 3. Tencent Zhuque Lab demonstrated root on multiple distros, though no widespread public exploit has surfaced. Mitigate by upgrading to the patched kernels or blocking the SCTP module if not needed. The issue traces back to 2008 and affects many releases, with a related use-after-free fixed in the same patch; check your distro's tracker for coverage.
- 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers The Hacker News
- 18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host CyberSecurityNews
- Critical Linux SCTP Flaw Enables Root Access and Container Escape LinkedIn
- SCTPhantom Linux Kernel Flaw Lets Local Attackers Gain Root and Escape Containers cyberpress.org
- 18-year-old Linux SCTP bug allows root privileges secnews.gr
Reading Insights
Total Reads
0
Unique Readers
21
Time Saved
3 min
vs 4 min read
Condensed
84%
619 → 96 words
Want the full story? Read the original article
Read on The Hacker News