18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
AI Summary
A critical use-after-free vulnerability in Linux's SCTP implementation, tracked as CVE-2026-64564 and named SCTPhantom, has existed since 2008 and could allow local attackers to gain root privileges and escape containers. The flaw arises from improper handling of SCTP dynamic address reconfiguration, where a delete request is validated against one address but applied to another, leading to a use-after-free condition. Tencent's Zhuque Lab demonstrated successful exploitation on multiple Linux distributions, achieving host-level root access without requiring CAP_NET_ADMIN or CAP_SYS_ADMIN under specific conditions. The vulnerability was patched in Linux kernel versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148, released on August 3, 2026.
AI-extracted · verify before operational use