Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Reptiles, gold and money: How Australia is cracking down on wildlife trafficking

    September 23, 2026

    Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says
    • Reptiles, gold and money: How Australia is cracking down on wildlife trafficking
    • Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott
    • Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales
    • UK to fight Russian disinformation and push new global AI standards, Burnham says
    • Data centres: Developers hope fibre optics will cut power use
    • ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
    • $161 Million in Decade-Old Bitcoin Has Moved in Just Two Weeks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 9, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 07, 2026Linux / Vulnerability

    A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.

    The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

    Tracked as CVE-2026-64564 and named SCTPhantom by its finders, the flaw was disclosed publicly on August 6, two days after the kernel CVE team assigned it. No public exploit code had surfaced at the time of writing, and The Hacker News found no entry for the flaw in CISA’s Known Exploited Vulnerabilities catalog as of August 7.

    The flaw is local, not remote, and it needs SCTP reachable on the target, which limits exposure. Where those conditions held, Tencent Zhuque Lab reports it got root on the kernel builds it tested for Debian 13, Ubuntu 24.04, Rocky Linux 9 and RHEL 9, and OpenCloudOS.

    Cybersecurity

    SCTP is a transport protocol that lets one connection run over several network paths at once. A companion feature, dynamic address reconfiguration, lets a peer add or drop those addresses mid-connection.

    The bug is a mix-up over identity: the kernel checks a delete request against the packet’s source address, but acts on a path it picked using a different address inside the message. Per the kernel’s own advisory, one message can carry an address, a delete for that same address, then a wildcard delete. That sequence frees the path, then reuses the dead pointer, leaving the connection pointing at memory the kernel has already released.

    The patch refuses a delete aimed at the path the message is being processed against. The bug traces to Linux 2.6.25 in 2008 and has been in every kernel released since.

    Tencent’s container escape claim is based on its own testing. In its write-up, the lab says an early version of its exploit needed the net.sctp.addip_enable and net.sctp.addip_noauth_enable sysctls switched on, which made CAP_NET_ADMIN look like a prerequisite. It later found a route that leaves both untouched by enabling the features per socket instead.

    The lab says its escape test kept the default seccomp profile and granted neither CAP_NET_ADMIN nor CAP_SYS_ADMIN. By its count, six of eight attempts reached root on the host.

    No one outside the lab has reproduced any of that, and the write-up does not name the container runtime it tested against. The lab itself notes that socket access, seccomp profiles, and user-namespace policy all shift exposure elsewhere. An openKylin advisory covering the same bug goes no further than kernel panic and denial of service.

    Cybersecurity

    The severity number is unsettled too. Tencent scored it 8.5 under CVSS v4.0. NVD had assigned neither a score nor a weakness classification as of August 7.

    Vendors often backport fixes without moving to a new upstream version, so a kernel version string alone will not tell you whether you are covered; check your distribution’s tracker. A second dangling-transport use-after-free in the same code was patched on August 6, after the August 3 stable releases shipped, so those kernels do not carry it. Where SCTP is not needed, blocking the module removes the attack surface outright.

    Tencent credits the find to Corvus AI, a multi-agent research pipeline it built for kernel work, making SCTPhantom the latest in a run of long-dormant kernel flaws surfaced with machine assistance this year, alongside GhostLock in July. It also lands the same day as Zapscape, an unrelated KVM escape, and the same four stable releases carry both fixes.

    18YearOld Containers Escape Flaw gain Linux local Root SCTP users
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Rogue external MFA providers can steal passwords during logins

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    The Home Planet Fund succeeds by giving directly to local communities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Reptiles, gold and money: How Australia is cracking down on wildlife trafficking

    September 23, 2026

    Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott

    September 23, 2026

    Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Reptiles, gold and money: How Australia is cracking down on wildlife trafficking

    September 23, 2026

    Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.