Critical SCTP Vulnerability in Linux Kernel Allows Root Access and Container Escape

Critical SCTP Vulnerability in Linux Kernel Allows Root Access and Container Escape

First seen 8 Aug 2026, 08:06 UTC Feeds.4SysopsCybersecuritynews 79% similarity 69.8

Article Content

Browse articles
ThreatCluster

A serious Linux kernel vulnerability, identified as CVE-2026-64564 and named SCTPhantom, was disclosed on August 4, 2026. This use-after-free flaw in the SCTP Dynamic Address Reconfiguration feature enables local users to escalate privileges to root and escape containers. Tencent Zhuque Lab reported six successful host-root escapes in eight attempts, even under default seccomp profiles without elevated capabilities. The vulnerability poses a significant risk to systems running affected Linux kernel versions, allowing attackers to compromise the underlying host. The first public proof of concept (PoC) was released on August 7, 2026, raising immediate concerns about potential exploitation. System administrators are urged to monitor for signs of exploitation and apply necessary mitigations.

Key Points: • CVE-2026-64564, named SCTPhantom, allows local users to gain root access. • Successful exploitation reported by Tencent Zhuque Lab with a 75% success rate. • First public PoC released on August 7, 2026, increasing urgency for mitigation.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
CVE-2026-64564 published
Linux kernel vulnerability SCTPhantom disclosed, allowing privilege escalation and container escape.
Cybersecuritynews
2026-08-07
First public PoC released
Proof of concept for SCTPhantom vulnerability made public, increasing risk of exploitation.
Feeds.4Sysops
Recent
Successful exploits reported
Tencent Zhuque Lab confirmed six successful host-root escapes in eight attempts using the SCTPhantom flaw.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story