Home / Aug 08, 2026 / Story
0
#2 The Hacker News general August 07, 2026 at 11:10 UTC

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

By [email protected] (The Hacker News)

AI Summary

An 18-year-old use-after-free vulnerability in Linux's SCTP networking stack — present since 2008 — has been weaponized by Tencent researchers to achieve full root privilege escalation and container escape to the underlying host. Fixed in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148 released August 3, 2026, any environment running older kernels with SCTP reachable is at active risk and should patch immediately.

Relevance score: 90.0/100

# More from August 08