Skip to content
Critical SCTP Vulnerability in Linux Kernel Allows Root Access and Container Escape

Critical SCTP Vulnerability in Linux Kernel Allows Root Access and Container Escape

First seen 8 Aug 2026, 08:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 9, 2026 at 06:49 UTC
  • •CVE-2026-64564, named SCTPhantom, allows local users to gain root access.
  • •Successful exploitation reported by Tencent Zhuque Lab with a 75% success rate.
  • •First public PoC released on August 7, 2026, increasing urgency for mitigation.

A serious Linux kernel vulnerability, identified as CVE-2026-64564 and named SCTPhantom, was disclosed on August 4, 2026. This use-after-free flaw in the SCTP Dynamic Address Reconfiguration feature enables local users to escalate privileges to root and escape containers. Tencent Zhuque Lab reported six successful host-root escapes in eight attempts, even under default seccomp profiles without elevated capabilities. The vulnerability poses a significant risk to systems running affected Linux kernel versions, allowing attackers to compromise the underlying host. The first public proof of concept (PoC) was released on August 7, 2026, raising immediate concerns about potential exploitation. System administrators are urged to monitor for signs of exploitation and apply necessary mitigations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 56d ago How this analysis works

Timeline

2026-08-04
CVE-2026-64564 published
Linux kernel vulnerability SCTPhantom disclosed, allowing privilege escalation and container escape.
Cybersecuritynews
2026-08-07
First public PoC released
Proof of concept for SCTPhantom vulnerability made public, increasing risk of exploitation.
Feeds.4Sysops
Recent
Successful exploits reported
Tencent Zhuque Lab confirmed six successful host-root escapes in eight attempts using the SCTPhantom flaw.
Feeds.4Sysops

More articles in this cluster (3)

Following this threat?

Track CVE-2026-64564 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed