THREATOPS
THREAT OPSThreat News › CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape

CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape

medoss_secPublished 2026-08-06

<p>Posted by Fourie Zhang on Aug 06</p>Hi all,<br /> <br /> We are publishing details of SCTPhantom, CVE-2026-64564, a use-after-free<br /> in Linux SCTP Dynamic Address Reconfiguration.<br /> <br /> Impact:<br /> - Local low-privileged user -&gt; root on affected systems.<br /> - Container -&gt; host root.<br /> <br /> Bug:<br /> --------<br /> In the Linux kernel&apos;s SCTP implementation, sctp

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/457

Same event, other sources