Kryptovalutaticker:
sysadmin från Cyber Security News

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host

Guru Baran
5 hours ago
4 Visningar
0 Kommentarer
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host

A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers to compromise the underlying host. The flaw is a use-after-free bug in the kernel’s SCTP Dynamic Address Reconfiguration feature, and remarkably, its root cause traces back to code introduced in Linux 2.6.25 in December 2007, making it nearly 18 years old before discovery. The vulnerability lives in how the kernel handles ASCONF chunks, a mechanism defined in RFC 5061 that lets SCTP associations add, remove, or reconfigure network paths on the fly. The bug stems from an identity mismatch: the kernel validates a DEL-IP delete...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!