Critical Linux SCTP Flaw Enables Root Access and Container Escape
A critical vulnerability named 'SCTPhantom' has been discovered in the Linux kernel, potentially allowing attackers to gain root access or escape containers. The flaw has existed for 18 years, and administrators are urged to update their kernels immediately.
Why it matters
This is a major security risk for enterprise infrastructure and cloud environments that rely on Linux kernels.
A memory-safety vulnerability hidden in the Linux kernel for almost two decades can allow a low-privileged user to take complete control of affected systems and, under certain conditions, escape from a container to compromise the underlying host.
Tracked as CVE-2026-64564 and named SCTPhantom , the vulnerability is a use-after-free flaw in Linux’s implementation of the Stream Control Transmission Protocol, or SCTP. The affected code handles dynamic changes to the network addresses associated with an SCTP connection.
Researchers at T encent’s Zhuque Lab developed an exploit that converted the memory-corruption condition into reliable kernel-level privilege escalation. In tests, the researchers obtained root access on systems running Debian 13, Ubuntu 24.04, Rocky Linux 9 and Red Hat Enterprise Linux 9-family kernels, OpenCloudOS-based systems and a Linux 7.2 release-candidate research kernel.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in