SCTPhantom gives root on Linux. Do you need to care?

SCTPhantom, tracked as CVE-2026-64564, is a use-after-free in the Linux kernel's SCTP code dating to version 2.6.25 in 2007, rated 8.5 under CVSS v4.

It gives an unprivileged local user root on the host and allows a container escape, with no special capabilities required and default seccomp in place.

Fixed kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148 shipped on August 3, and unloading the SCTP module blocks the bug on hosts that cannot patch yet.

Read the full post

Read the full post