CVE Tools
Back to feed
PoC public Linux Kernel privilege-escalation Debian

Уязвимость SCTPhantom существовала в коде Linux 18 лет

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Tencent researchers identified a use-after-free vulnerability dubbed SCTPhantom that has persisted in the Linux kernel since version 2.6.25 in 2008. Tracked as CVE-2026-64564, the flaw resides in the Stream Control Transmission Protocol implementation and enables local privilege escalation to root, with a demonstrated proof-of-concept for container escape. The issue stems from inconsistent address handling during dynamic reconfiguration of active connections.

Fixed versions include kernel releases 7.1.6, 6.18.42, 6.12.101, and 6.6.148.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store