Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Whirling Like Dervishes in Turkey, but Open to Everyone

    August 9, 2026

    Today’s the last day to get up to $400 off your TechCrunch Disrupt 2026 ticket

    August 9, 2026

    Institutional bear market: Why Bitcoin’s downturn is different

    August 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Whirling Like Dervishes in Turkey, but Open to Everyone
    • Today’s the last day to get up to $400 off your TechCrunch Disrupt 2026 ticket
    • Institutional bear market: Why Bitcoin’s downturn is different
    • Amazon deforestation alerts fall to lowest level since 2013, Brazilian data show
    • Bald Range Wildfire Forces Evacuation of 18,000 in British Columbia
    • Is this $450 laptop from an unknown brand too good to be true?
    • 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
    • Bitcoin, XRP, Solana and Tron beat Ethereum and Cardano every month since 2022 on investor buying
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, August 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 9, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 07, 2026Linux / Vulnerability

    A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.

    The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

    Tracked as CVE-2026-64564 and named SCTPhantom by its finders, the flaw was disclosed publicly on August 6, two days after the kernel CVE team assigned it. No public exploit code had surfaced at the time of writing, and The Hacker News found no entry for the flaw in CISA’s Known Exploited Vulnerabilities catalog as of August 7.

    The flaw is local, not remote, and it needs SCTP reachable on the target, which limits exposure. Where those conditions held, Tencent Zhuque Lab reports it got root on the kernel builds it tested for Debian 13, Ubuntu 24.04, Rocky Linux 9 and RHEL 9, and OpenCloudOS.

    Cybersecurity

    SCTP is a transport protocol that lets one connection run over several network paths at once. A companion feature, dynamic address reconfiguration, lets a peer add or drop those addresses mid-connection.

    The bug is a mix-up over identity: the kernel checks a delete request against the packet’s source address, but acts on a path it picked using a different address inside the message. Per the kernel’s own advisory, one message can carry an address, a delete for that same address, then a wildcard delete. That sequence frees the path, then reuses the dead pointer, leaving the connection pointing at memory the kernel has already released.

    The patch refuses a delete aimed at the path the message is being processed against. The bug traces to Linux 2.6.25 in 2008 and has been in every kernel released since.

    Tencent’s container escape claim is based on its own testing. In its write-up, the lab says an early version of its exploit needed the net.sctp.addip_enable and net.sctp.addip_noauth_enable sysctls switched on, which made CAP_NET_ADMIN look like a prerequisite. It later found a route that leaves both untouched by enabling the features per socket instead.

    The lab says its escape test kept the default seccomp profile and granted neither CAP_NET_ADMIN nor CAP_SYS_ADMIN. By its count, six of eight attempts reached root on the host.

    No one outside the lab has reproduced any of that, and the write-up does not name the container runtime it tested against. The lab itself notes that socket access, seccomp profiles, and user-namespace policy all shift exposure elsewhere. An openKylin advisory covering the same bug goes no further than kernel panic and denial of service.

    Cybersecurity

    The severity number is unsettled too. Tencent scored it 8.5 under CVSS v4.0. NVD had assigned neither a score nor a weakness classification as of August 7.

    Vendors often backport fixes without moving to a new upstream version, so a kernel version string alone will not tell you whether you are covered; check your distribution’s tracker. A second dangling-transport use-after-free in the same code was patched on August 6, after the August 3 stable releases shipped, so those kernels do not carry it. Where SCTP is not needed, blocking the module removes the attack surface outright.

    Tencent credits the find to Corvus AI, a multi-agent research pipeline it built for kernel work, making SCTPhantom the latest in a run of long-dormant kernel flaws surfaced with machine assistance this year, alongside GhostLock in July. It also lands the same day as Zapscape, an unrelated KVM escape, and the same four stable releases carry both fixes.

    18YearOld Containers Escape Flaw gain Linux local Root SCTP users
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Growing Up The Hard Way

    UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

    Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    Critical Vulnerabilities Patched With Chrome 151 Update

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Whirling Like Dervishes in Turkey, but Open to Everyone

    August 9, 2026

    Today’s the last day to get up to $400 off your TechCrunch Disrupt 2026 ticket

    August 9, 2026

    Institutional bear market: Why Bitcoin’s downturn is different

    August 9, 2026

    Amazon deforestation alerts fall to lowest level since 2013, Brazilian data show

    August 9, 2026
    Latest Posts

    With Hopes High for New H.I.V. Prevention Pill, Merck Takes Steps to Ensure Access

    July 24, 2026

    Trump to speak at rescheduled White House Correspondents’ Dinner following failed April shooting

    July 24, 2026

    When is an apology not an apology? When it comes from an AI boss with an out-of-control chatbot | Marina Hyde

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Whirling Like Dervishes in Turkey, but Open to Everyone

    August 9, 2026

    Today’s the last day to get up to $400 off your TechCrunch Disrupt 2026 ticket

    August 9, 2026

    Institutional bear market: Why Bitcoin’s downturn is different

    August 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.