Crypto Ticker:
sysadmin from Cyber Security News

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host

Guru Baran
5 hours ago
5 Views
0 Comments
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host

A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers to compromise the underlying host. The flaw is a use-after-free bug in the kernel’s SCTP Dynamic Address Reconfiguration feature, and remarkably, its root cause traces back to code introduced in Linux 2.6.25 in December 2007, making it nearly 18 years old before discovery. The vulnerability lives in how the kernel handles ASCONF chunks, a mechanism defined in RFC 5061 that lets SCTP associations add, remove, or reconfigure network paths on the fly. The bug stems from an identity mismatch: the kernel validates a DEL-IP delete...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!