THREAT OPS › Threat News › Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
<p>Posted by Emily Shepherd on Aug 06</p>I notice there is no mitigation section in the write up. Can you confirm <br /> if unloading / blacklisting the sctp module - on a system where this <br /> isn't built into the kernel - would protect against this exploit.<br /> <br /> Thanks,<br /> <br /> Emily<br />
Indicators of compromise
- CVE-2026-64564cve
Original source: https://seclists.org/oss-sec/2026/q3/458
Same event, other sources
- [NVD] CVE-2026-64564 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(nvd · 2026-08-04
- CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06