An 18-year-old use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and dubbed SCTPhantom, allows local users to gain root privileges and potentially escape container environments. Tencent researchers demonstrated the flaw on multiple Linux distributions, although exploitation requires SCTP to be enabled, and mitigation patches have been released in recent stable kernel versions. Users are advised to update kernels to the fixed versions or disable SCTP if unused to reduce the attack surface.
https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html

