AI Stories on SHORT INFO are generated & curated with AI
unverified 08 Aug, 10:10

18-year-old Linux kernel bug SCTPhantom (CVE-2026-64564) lets local attackers gain root and escape containers

A Linux kernel bug dating to 2007 lets a local attacker become root and escape containers. Tracked as CVE-2026-64564 (SCTPhantom), it was confirmed exploitable on Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9 and OpenCloudOS. Patches are already backported to stable kernel branc

A Linux kernel vulnerability that has gone unnoticed since December 2007 lets a local attacker escalate to root privileges and, in some configurations, escape containers to reach the host system. Tracked as CVE-2026-64564 and named SCTPhantom by Tencent's Zhuque Lab, the bug is a use-after-free flaw in the kernel's SCTP protocol, specifically its Dynamic Address Reconfiguration (ASCONF) feature. An attacker can craft a sequence of network messages that removes a live transport connection while the kernel still holds stale pointers referencing it, opening the door to memory corruption and privilege escalation. Tencent's researchers confirmed they achieved full root access on tested kernel builds of Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9 and OpenCloudOS. Because exploitation requires local access, the risk is highest on shared and multi-tenant systems, cloud hosting platforms and CI/CD infrastructure, where one compromised process or tenant could escalate to control the entire host. Fixes have already been backported to stable Linux kernel branches 6.6.148, 6.12.101, 6.18.42 and 7.1.6. The bug was disclosed publicly on August 6, two days after receiving its CVE assignment. SCTPhantom was found by Corvus AI, an automated multi-agent research pipeline Tencent built specifically for kernel auditing, making it the latest in a series of long-dormant Linux kernel bugs surfaced with AI assistance this year. Sources: Tencent Zhuque Lab, The Hacker News.

Published on
BlueskyRedditThreadsFacebookX