Feeds.4Sysops Critical SCTP Vulnerability in Linux Kernel Allows Root Access and Container Escape
Article Content
- •CVE-2026-64564, named SCTPhantom, allows local users to gain root access.
- •Successful exploitation reported by Tencent Zhuque Lab with a 75% success rate.
- •First public PoC released on August 7, 2026, increasing urgency for mitigation.
A serious Linux kernel vulnerability, identified as CVE-2026-64564 and named SCTPhantom, was disclosed on August 4, 2026. This use-after-free flaw in the SCTP Dynamic Address Reconfiguration feature enables local users to escalate privileges to root and escape containers. Tencent Zhuque Lab reported six successful host-root escapes in eight attempts, even under default seccomp profiles without elevated capabilities. The vulnerability poses a significant risk to systems running affected Linux kernel versions, allowing attackers to compromise the underlying host. The first public proof of concept (PoC) was released on August 7, 2026, raising immediate concerns about potential exploitation. System administrators are urged to monitor for signs of exploitation and apply necessary mitigations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-64564 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Vulnerabilities in SUSE Linux Kernel Patches Released SUSE has released critical security patches for various versions of its Linux Enterprise Kernel due to multiple vulnerabilities, including CVE-2026-46150, CVE-2026-53360, CVE-2026-64423, CVE-2026-64561, CVE-2026-64564, and CVE-2026-68138. These vulnerabilities can allow attackers to gain administrative control over…
Multiple Vulnerabilities in SUSE Linux Systems Require Urgent Attention SUSE has released updates addressing multiple vulnerabilities across its Linux products, including SUSE Linux Enterprise Server and SAP applications. The vulnerabilities include CVE-2026-46150 (CVSS 7.1), CVE-2026-53360 (CVSS 8.8), CVE-2026-64423 (CVSS 7.8), CVE-2026-64561 (CVSS 9.3), and CVE-2026-68138 (CVSS 7.8).…