Tag

Cve 2026 64564

All articles tagged with #cve 2026 64564

Ancient Linux SCTP bug lets local attackers gain root and escape containers
security16 days ago

Ancient Linux SCTP bug lets local attackers gain root and escape containers

A long-standing use-after-free in Linux SCTP (CVE-2026-64564, nicknamed SCTPhantom) can allow a local user to gain root on a host and escape containers when SCTP is reachable; patches landed in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148 as of August 3. Tencent Zhuque Lab demonstrated root on multiple distros, though no widespread public exploit has surfaced. Mitigate by upgrading to the patched kernels or blocking the SCTP module if not needed. The issue traces back to 2008 and affects many releases, with a related use-after-free fixed in the same patch; check your distro's tracker for coverage.