Digest
CRITICAL

18-Year-Old Linux SCTP Flaw Allows Root and Container Escape

A use-after-free bug in Linux’s SCTP networking code, present since 2008, can be exploited to gain full root privileges on a host. Tencent researchers demonstrated its use to escape a container and access the underlying machine. Fixes have been released in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148; users with older kernels and reachable SCTP should update immediately.

← Back to the feed

Trending Tags