THREAT OPS › Threat News › Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape
<p>Posted by Solar Designer on Aug 06</p>Hi,<br /> <br /> Thank you for bringing this to oss-security.<br /> <br /> On these distros, the SCTP module is not part of a typical install, but<br /> is in the kernel-modules-extra subpackage.<br /> <br /> Further, that subpackage includes module blacklist files with:<br /> <br /> blacklist sctp<br /> blacklist sctp_diag<br /> <br /> which prevents unpri
Indicators of compromise
- CVE-2026-64564cve
Original source: https://seclists.org/oss-sec/2026/q3/467
Same event, other sources
- [NVD] CVE-2026-64564 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(nvd · 2026-08-04
- CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06