THREAT OPS › Threat News › [NVD] CVE-2026-64564 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing
sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv(
[NVD] CVE-2026-64564 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(
CVE-2026-64564 CVSS: 9.8 CRITICAL Published: 2026-08-04T07:16:31.340
In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing
sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Para
Indicators of compromise
- CVE-2026-64564cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64564
Same event, other sources
- CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06
- Re: CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escapeoss_sec · 2026-08-06