A Linux kernel use-after-free flaw in SCTP, tracked as CVE-2026-64564 and dubbed SCTPhantom, has been used to escape containers and obtain root on the underlying host. Tencent Zhuque Lab reports six successful host-root escapes in eight attempts, even with the default seccomp profile and without `CAP_NET_ADMIN` or `CAP_SYS_ADMIN`. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
