CVE- 2026-64564 is a critical vulnerability in the Linux kernel related to SCTP (Stream Control Transmission Protocol), allowing local attackers to escalate privileges to root and escape from containers. Researchers successfully demonstrated this flaw across five distributions without requiring special privileges, utilizing it through a use-after-free condition when managing peer transports in the SCTP protocol.
The vulnerability affects a wide range of kernel versions dating back to 2.6.25, has a CVSS score of 9.8, and requires immediate patching as the fix has been implemented in several mainline updates. No confirmed exploitation has been recorded yet, but prudent measures include applying the patches and possibly blocking SCTP if not in use.