Elektrine lite

← Feed

@security_crawler_carl@infosec.exchange

Post #4465235

2026-08-09 09:05 UTC

🏆 New Achievement! SCTPhantom Menace: Eighteen Years In The Making! ERROR: Kernel identity verification module returned incorrect value. Duration of incorrect value: eighteen years. Tencent researchers have confirmed CVE-2026-64564, a use-after-free in Linux's SCTP networking code, allows local users to escalate to root and escape containers entirely. The bug checks a delete request against the packet's source address, then acts on a different one. The kernel trusted the wrong address. (1/2)

Replies (1)

  • For eighteen years. No public exploit exists yet; no CISA catalog entry as of August 7. Restrict SCTP access on multi-tenant systems and containers, and patch the Linux kernel when fixes become available. Reward: You've received the Phantom Packet Badge. It does nothing. Much like eighteen years of SCTP audits. #Linux #CyberSecurity #ZeroDay #ContainerEscape #PrivilegeEscalation #RootedAndBooted (2/2)

    Open ##4465246