#2
The Hacker News
general
August 07, 2026 at 11:10 UTC
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
By [email protected] (The Hacker News)
AI Summary
An 18-year-old use-after-free vulnerability in Linux's SCTP networking stack — present since 2008 — has been weaponized by Tencent researchers to achieve full root privilege escalation and container escape to the underlying host. Fixed in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148 released August 3, 2026, any environment running older kernels with SCTP reachable is at active risk and should patch immediately.
Relevance score: 90.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →