CVE-2026-64564
EPSS 1% (71st percentile). Microsoft patch: CBL-Mariner Releases.
Vulnerabilities · 52 days ago
A local Linux kernel bug is only “local” if you ignore the container boundary. In SCTP, a user or workload that can reach the code path may break out to the host kernel, then inherit control over the node that runs sibling containers too.
Tencent says the use-after-free, tracked as CVE-2026-64564 and nicknamed SCTPhantom, has existed since 2008 and can be driven to root on Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, and OpenCloudOS builds it tested. Stable fixes shipped August 3 in kernel lines 7.1.6, 6.18.42, 6.12.101, and 6.6.148.
The practical risk is the node, not just the workload. If SCTP is reachable on an older kernel, one compromised container can become host root and put every other workload on that machine in play.
EPSS 1% (71st percentile). Microsoft patch: CBL-Mariner Releases.
1 source covering this story
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
Linux SCTP flaw CVE-2026-64564 dates back to 2008 and Tencent researchers say it could escape containers and gain host root.
Part of the PlainSec briefing for 2026-08-10