< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-07T16:40:33+05:30

18-Year-Old Linux SCTP Vulnerability Allows Local Privilege Escalation and Container Escape

A critical use-after-free vulnerability in Linux's SCTP protocol, dating back to 2008, allows local users to gain root privileges and escape containers. The flaw was patched in recent kernel versions, but systems using older kernels remain at risk.

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.

The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

Read original article

*** END OF TRANSMISSION ***