oss-sec mailing list archives
Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
From: "Emily Shepherd" <emily () redcoat dev>
Date: Thu, 06 Aug 2026 16:29:42 +0100
On Thu Aug 6, 2026 at 12:33 PM BST, Fourie Zhang wrote:
Hi all, We are publishing details of SCTPhantom, CVE-2026-64564, a use-after-free in Linux SCTP Dynamic Address Reconfiguration. Impact: - Local low-privileged user -> root on affected systems. - Container -> host root.
I notice there is no mitigation section in the write up. Can you confirm if unloading / blacklisting the sctp module - on a system where this isn't built into the kernel - would protect against this exploit. Thanks, Emily
Current thread:
- CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Fourie Zhang (Aug 06)
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Emily Shepherd (Aug 06)
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape Solar Designer (Aug 06)
