BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux SCTP bug allows full container escape, root access

Linux SCTP flaw enables root access and container escape.

  • CVE-2026-64564 (SCTPhantom) is a use-after-free bug in Linux’s SCTP networking code that can escalate to full root access and container escape.
  • The flaw has existed since 2008; fixes shipped August 3 in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148.
  • Tencent Zhuque Lab demonstrated container escape achieving host root on Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS.
  • The local flaw requires SCTP reachable on the target; Tencent scored it 8.5 under CVSS v4.0.
  • A second related use-after-free in the same code was patched August 6, after the stable releases shipped.

Tencent‘s Zhuque Lab disclosed a critical use-after-free vulnerability in Linux’s SCTP networking code on August 6, 2026, demonstrating it can escalate to full root and escape containers. Tracked as CVE-2026-64564 and named SCTPhantom, the flaw originated in Linux 2.6.25 back in 2008, and fixed kernels shipped August 3.

- Advertisement -

The vulnerability is local, not remote, and requires SCTP reachable on the target. However, where those conditions held, Tencent researchers achieved root on kernel builds for Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS.

The bug stems from an identity mix-up: the kernel checks a delete request against the packet’s source address but acts on a path selected using a different address. Per the NVD advisory, one message can carry an address, a delete for that same address, then a wildcard delete, freeing the path and reusing a dead pointer.

The patch refuses a delete aimed at the path being processed against. Tencent‘s write-up explains an early exploit required specific sysctls, but later found a route leaving them untouched by enabling features per socket.

The lab says its escape test kept the default seccomp profile without CAP_NET_ADMIN or CAP_SYS_ADMIN, with six of eight attempts reaching host root. However, no one outside the lab has reproduced the escape, and an openKylin advisory only reports kernel panic and denial of service.

- Advertisement -

Tencent scored the flaw 8.5 under CVSS v4.0, while NVD had not assigned a score as of August 7. Meanwhile, a second dangling-transport use-after-free in the same code was patched August 6, after the stable releases shipped.

The find came through Corvus AI, Tencent‘s multi-agent research pipeline, making SCTPhantom the latest long-dormant kernel flaw surfaced with machine assistance. It landed the same day as Zapscape, an unrelated KVM escape, with both fixes in the same four stable releases.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

GTA V mod adds 235 simulated Flock cameras to track players

Modder WTTDOTM has added 235 simulated Flock surveillance cameras to Grand Theft Auto V.The...

Tom Lee: Inflation Less Severe; Bullish on Ethereum

Tom Lee argues portfolio fees and flash memory prices distort inflation metrics, making the...

PayPal CEO rejects $50B buyout, charts an independent future

Paypal CEO Enrique Lores has rejected a buyout offer exceeding $50 billion from rival...

Bitcoin Suisse to shift up to half of its Swiss jobs abroad.

Bitcoin Suisse plans to relocate up to 60 of its 120 Swiss positions, primarily...

OpenAI Asks Congress if AI Rivals Can Legally Slow Development

OpenAI has asked lawmakers whether rival AI developers could legally coordinate a slowdown, according...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading