Уязвимость SCTPhantom существовала в коде Linux 18 лет
PoC publicLinux KernelOur summary
Tencent researchers identified a use-after-free vulnerability dubbed SCTPhantom that has persisted in the Linux kernel since version 2.6.25 in 2008. Tracked as CVE-2026-64564, the flaw resides in the Stream Control Transmission Protocol implementation and enables local privilege escalation to root, with a demonstrated proof-of-concept for container escape. The issue stems from inconsistent address handling during dynamic reconfiguration of active connections.
Fixed versions include kernel releases 7.1.6, 6.18.42, 6.12.101, and 6.6.148.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.