18-year Linux SCTP flaw lets attackers escalate root
π‘οΈ A long-standing use-after-free bug in Linux's SCTP implementation, tracked as CVE-2026-64564 and called SCTPhantom, can be exploited to achieve local privilege escalation and, according to Tencent Zhuque Lab, to escape containers and reach the host. Stable kernel fixes (7.1.6, 6.18.42, 6.12.101 and 6.6.148) were released on August 3. Systems with reachable SCTP should apply vendor updates or disable the module if unused.
