THREAT OPS › Threat News › CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
<p>Posted by Fourie Zhang on Aug 06</p>Hi all,<br /> <br /> We are publishing details of SCTPhantom, CVE-2026-64564, a use-after-free<br /> in Linux SCTP Dynamic Address Reconfiguration.<br /> <br /> Impact:<br /> - Local low-privileged user -> root on affected systems.<br /> - Container -> host root.<br /> <br /> Bug:<br /> --------<br /> In the Linux kernel's SCTP implementation, sctp
Indicators of compromise
- CVE-2026-64564cve
Original source: https://seclists.org/oss-sec/2026/q3/457
Same event, other sources
- [NVD] CVE-2026-64564 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(nvd · 2026-08-04
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06