A critical Linux kernel vulnerability affecting Linux versions The vulnerable code dates back to Linux 2, tracked as CVE-2026-64564 with a CVSS score of 9.8 (Critical · CVSSv3), is a use-after-free in SCTP that allows local attackers to gain root privilege escalation and container-to-host escape on various distributions. The flaw breaks a core container security boundary, enabling an attacker inside a container to reach the shared host kernel and run code in the host’s initial namespaces, effectively acting as host root. This vulnerability is linked to SCTP Dynamic Address Reconfiguration with an identity mismatch between packet source address and ASCONF transport chosen through the ASCONF Address Parameter. A crafted ASCONF sequence removes one transport yet reuses its stale pointer, resulting in a dangling reference in the association’s primary and active path. The attack works by chaining this use-after-free into a kernel read primitive, KASLR recovery, and a data-oriented commit_creds call for global root. Affected versions include Linux kernels dating back to 2.6.25, which affects a wide range of kernels and vendor builds. The upstream fix rejects deletion of the retained transport for the ASCONF chunk and mirrors the existing source-address guard.
We recommend you to update Linux to mention version: 6.6.y: 6.6.148 6.12.y: 6.12.101 6.18.y: 6.18.42 7.1.y: 7.1.6[/subscribe_to_unlock_form]
A critical Linux kernel vulnerability affecting Linux versions The vulnerable code dates back to Linux 2, tracked as CVE-2026-64564 with a CVSS score of 9.8 (Critical · CVSSv3), is a use-after-free in SCTP that allows local attackers to gain root privilege escalation and container-to-host escape on various distributions. The flaw breaks a core container security boundary, enabling an attacker inside a container to reach the shared host kernel and run code in the host’s initial namespaces, effectively acting as host root. This vulnerability is linked to SCTP Dynamic Address Reconfiguration with an identity mismatch between packet source address and ASCONF transport chosen through the ASCONF Address Parameter. A crafted ASCONF sequence removes one transport yet reuses its stale pointer, resulting in a dangling reference in the association’s primary and active path. The attack works by chaining this use-after-free into a kernel read primitive, KASLR recovery, and a data-oriented commit_creds call for global root. Affected versions include Linux kernels dating back to 2.6.25, which affects a wide range of kernels and vendor builds. The upstream fix rejects deletion of the retained transport for the ASCONF chunk and mirrors the existing source-address guard.
We recommend you to update Linux to mention version: 6.6.y: 6.6.148 6.12.y: 6.12.101 6.18.y: 6.18.42 7.1.y: 7.1.6[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]