LIVE · cybersecurity feed
Live wire

sctp

CVE-2026-64564high

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

An 18-year-old use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and named SCTPhantom, has been patched. The flaw, present since 2008, could allow local users to gain root privileges and escape containerized environments. Researchers from Tencent successfully demonstrated root access and container escape on several Linux distributions.