Infosec News Nuggets — August 10, 2026
Brief
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug tracked as CVE-2026-64564 and nicknamed SCTPhantom has been lurking in Linux’s SCTP networking code since 2008 and can be chained into full root access on a host; researchers say they used it to escape a container and reach the underlying machine, getting root on kernel builds for Debian 13, Ubuntu 24. 04, Rocky Linux 9, RHEL 9, and OpenCloudOS in six of eight attempts.
The bug stems from a mismatch between the address used to validate a delete request and the address used to pick the actual network path, letting an attacker free a live connection object and reuse the dangling pointer. Fixed stable kernels shipped August 3, and since exploitation requires local access with SCTP reachable, blocking the module where it’s unneeded removes the exposure entirely.
Levi Strauss & Co.
