BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux SCTP bug allows full container escape, root access

  • CVE-2026-64564 (SCTPhantom) is a use-after-free bug in Linux’s SCTP networking code that can escalate to full root access and container escape.
  • The flaw has existed since 2008; fixes shipped August 3 in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148.
  • Tencent Zhuque Lab demonstrated container escape achieving host root on Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS.
  • The local flaw requires SCTP reachable on the target; Tencent scored it 8.5 under CVSS v4.0.
  • A second related use-after-free in the same code was patched August 6, after the stable releases shipped.

Tencent‘s Zhuque Lab disclosed a critical use-after-free vulnerability in Linux’s SCTP networking code on August 6, 2026, demonstrating it can escalate to full root and escape containers. Tracked as CVE-2026-64564 and named SCTPhantom, the flaw originated in Linux 2.6.25 back in 2008, and fixed kernels shipped August 3.

- Advertisement -

The vulnerability is local, not remote, and requires SCTP reachable on the target. However, where those conditions held, Tencent researchers achieved root on kernel builds for Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS.

The bug stems from an identity mix-up: the kernel checks a delete request against the packet’s source address but acts on a path selected using a different address. Per the NVD advisory, one message can carry an address, a delete for that same address, then a wildcard delete, freeing the path and reusing a dead pointer.

The patch refuses a delete aimed at the path being processed against. Tencent‘s write-up explains an early exploit required specific sysctls, but later found a route leaving them untouched by enabling features per socket.

The lab says its escape test kept the default seccomp profile without CAP_NET_ADMIN or CAP_SYS_ADMIN, with six of eight attempts reaching host root. However, no one outside the lab has reproduced the escape, and an openKylin advisory only reports kernel panic and denial of service.

- Advertisement -

Tencent scored the flaw 8.5 under CVSS v4.0, while NVD had not assigned a score as of August 7. Meanwhile, a second dangling-transport use-after-free in the same code was patched August 6, after the stable releases shipped.

The find came through Corvus AI, Tencent‘s multi-agent research pipeline, making SCTPhantom the latest long-dormant kernel flaw surfaced with machine assistance. It landed the same day as Zapscape, an unrelated KVM escape, with both fixes in the same four stable releases.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

ASML: The Secret Engine Behind AI Chip Giants

ASML is the world’s sole manufacturer of extreme ultraviolet (EUV) lithography machines, essential for...

Tokenized RWA Deposits Triple to $7.4B, DeFi Falls 15%

Deposits of tokenized real-world assets into DeFi lending venues and exchanges more than tripled...

Crypto perp futures volume hits 31-month low at $4T

Crypto perpetual futures trading volume on centralized exchanges dropped to $4 trillion in July,...

AI discovers new HTTP desync attacks, 700+ sites at risk

PortSwigger's AI system, HTTP Terminator, autonomously generated and validated novel HTTP desynchronization attacks after...

US Senate Delays Crypto Clarity Act Vote Until September

The U.S. Senate will not vote on the Clarity Act before its August recess,...

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading