A Linux kernel use-after-free flaw in SCTP, tracked as CVE-2026-64564 and dubbed SCTPhantom, has been used to escape containers and obtain root on the underlying host. Tencent Zhuque Lab reports six successful host-root escapes in eight attempts, even with the default seccomp profile and without `CAP_NET_ADMIN` or `CAP_SYS_ADMIN`. Source
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!