18-year-old Linux kernel flaw (SCTPhantom, CVE-2026-64564) lets attackers escape containers and grab root
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64564 and named SCTPhantom, has existed since 2008. Tencent's security researchers say it lets a local attacker escape a container and gain full root access on the host. According to The Hacker News and the Nationa
A Linux kernel vulnerability that has existed since 2008 was publicly disclosed on August 6, 2026. Tracked as CVE-2026-64564 and named SCTPhantom by the researchers who found it, the bug is a use-after-free flaw in the kernel's SCTP networking code. Tencent's Zhuque Lab says it used the flaw to escape a container and reach full root access on the underlying host, succeeding in six of eight attempts under a default security profile with no extra permissions granted. The lab tested successfully against Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9 and OpenCloudOS builds. A fix already shipped in stable kernel releases 7.1.6, 6.18.42, 6.12.101 and 6.6.148 on August 3, three days before the public disclosure. Tencent rates the flaw 8.5 out of 10 under CVSS v4.0; the National Vulnerability Database had not yet assigned an official score as of August 7. No public exploit code had surfaced and the flaw was not yet listed in CISA's Known Exploited Vulnerabilities catalog as of that date. Source: The Hacker News, National Vulnerability Database (NVD).