securityonline.info 8/10/2026, 2:27:14 AM · external

Critical Linux Kernel SCTP Flaw Lets Attackers Gain Root Access

Critical Linux Kernel SCTP Flaw Lets Attackers Gain Root Access
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CVE- 2026-64564 is a critical vulnerability in the Linux kernel related to SCTP (Stream Control Transmission Protocol), allowing local attackers to escalate privileges to root and escape from containers. Researchers successfully demonstrated this flaw across five distributions without requiring special privileges, utilizing it through a use-after-free condition when managing peer transports in the SCTP protocol.

The vulnerability affects a wide range of kernel versions dating back to 2.6.25, has a CVSS score of 9.8, and requires immediate patching as the fix has been implemented in several mainline updates. No confirmed exploitation has been recorded yet, but prudent measures include applying the patches and possibly blocking SCTP if not in use.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline