A Linux kernel use-after-free flaw in SCTP, tracked as CVE-2026-64564 and dubbed SCTPhantom, has been used to escape containers and obtain root on the underlying host. Tencent Zhuque Lab reports six successful host-root escapes in eight attempts, even with the default seccomp profile and without `CAP_NET_ADMIN` or `CAP_SYS_ADMIN`. Source
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!