HIGH: Linux Kernel SCTP Flaw CVE-2026-64564 Enables Local Root and Container Escape
Tencent's Zhuque Lab disclosed SCTPhantom, an 18 year old use after free flaw in the Linux kernel SCTP code tracked as CVE-2026-64564. A local unprivileged user can escalate to root and, in the researchers' testing, escape containers to take over the host. Patched stable kernels shipped August 3, 2026.