A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers to compromise the underlying host. The flaw is a use-after-free bug in the kernel’s SCTP Dynamic Address Reconfiguration feature, and remarkably, its root cause traces back to code introduced in Linux 2.6.25 in December 2007, making it nearly 18 years old before discovery. The vulnerability lives in how the kernel handles ASCONF chunks, a mechanism defined in RFC 5061 that lets SCTP associations add, remove, or reconfigure network paths on the fly. The bug stems from an identity mismatch: the kernel validates a DEL-IP delete...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!