SCTPhantom — a vulnerability in the Linux kernel that provides root access and container escape.
A vulnerability (CVE-2026-64564) has been identified in the SCTP protocol implementation provided in the Linux kernel, allowing a local user to gain root privileges on the system. Among other issues, this vulnerability allows root access to the main system when an exploit is launched in an isolated container. A prototype of the exploit has been prepared, and its operation has been demonstrated in the Debian 13, Rocky Linux 9, RHEL 9, and Ubuntu 24.04 distributions with kernels 5.14, 6.6, […]
