Container Escape Turns Old Linux Bug into Host Risk

A local Linux kernel bug is only “local” if you ignore the container boundary. In SCTP, a user or workload that can reach the code path may break out to the host kernel, then inherit control over the node that runs sibling containers too. Tencent says the use-after-free, tracked as CVE-2026-64564 and nicknamed SCTPhantom, has existed since 2008 and can be driven to root on Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS builds it tested. Stable fixes shipped August 3 in kernel lines 7.1.6, 6.18.42, 6.12.101, and 6.6.148. The practical risk is the node, not just the workload. If SCTP is reachable on an older kernel, one compromised container can become host root and put every other workload on that machine in play.

Part of the PlainSec briefing for 2026-08-07

Editions

Sources