
An 18-year-old use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and named SCTPhantom, has been patched. The flaw, present since 2008, could allow local users to gain root privileges and escape containerized environments. Researchers from Tencent successfully demonstrated root access and container escape on several Linux distributions.

Nebula Security has revealed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present for 15 years. This flaw allows any logged-in user to achieve root privileges and container escape on unpatched systems, as it is included by default in most Linux distributions.