A long-standing Linux kernel flaw in SCTP Dynamic Address Reconfiguration, tracked as CVE-2026-64564 and dubbed SCTPhantom, was disclosed as a deterministic use-after-free bug that can let a low-privileged local user gain root privileges and potentially escape from a container to the host. The vulnerability affects ASCONF handling, where a crafted sequence of DEL-IP operations can free an SCTP transport and later reuse the dangling pointer. Researchers said the vulnerable logic dates back to Linux 2.6.25 and reported successful exploitation on Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9-family systems, OpenCloudOS, and a Linux 7.2 release candidate, including multiple tested host-root container escapes.
Fixes are available in mainline commit 9b2854f86f0b and in stable kernel releases 6.6.148, 6.12.101, 6.18.42, 7.1.6, and 7.2-rc5. Discussion on the oss-sec mailing list noted that practical exposure varies by distribution: on Rocky Linux 9 and RHEL 9-family systems, SCTP is typically not installed by default because it resides in the kernel-modules-extra package and is blacklisted for autoload, meaning administrators would generally need to explicitly install and load the module for the bug to be reachable. Defenders were urged to patch affected kernels or disable SCTP where it is not required.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Solar Designer replied that on Rocky Linux 9 and RHEL 9-family systems, SCTP is typically not installed by default because it resides in kernel-modules-extra and is blacklisted for autoload. He said exploitation on those systems generally requires an administrator to explicitly install and load SCTP, limiting practical exposure mainly to systems intentionally using it.
In an oss-sec reply, Emily Shepherd noted the write-up lacked a mitigation section and asked whether unloading or blacklisting the SCTP kernel module would protect systems where SCTP is not built in. The message did not provide a confirmed answer.
Fourie Zhang of the TencentOS Security Team and Tencent Zhuque Lab publicly disclosed CVE-2026-64564 on the oss-sec mailing list, describing local root escalation and container escape impact. The disclosure included technical details, affected fixed versions, and validation across Debian 13, Ubuntu 24.04, Rocky Linux 9/RHEL 9-family systems, and a 7.2-rc2 research kernel.
The Linux kernel CVE team assigned the identifier CVE-2026-64564 two days before the public disclosure. The issue covers a use-after-free in Linux SCTP Dynamic Address Reconfiguration.
Linux stable kernel releases 6.6.148, 6.12.101, 6.18.42, and 7.1.6 were released with fixes for the SCTPhantom vulnerability. The mainline fix is identified as commit 9b2854f86f0b, and 7.2-rc5 is also listed as fixed.
Private disclosure of the Linux SCTP use-after-free vulnerability later tracked as CVE-2026-64564 began on July 12, 2026. This predates the CVE assignment and subsequent public disclosure of SCTPhantom.
The SCTP ASCONF transport handling flaw later tracked as CVE-2026-64564 dates back to Linux 2.6.25. The disclosure ties the vulnerable sequence to commit 42e30bf3463c in 2008.
A public exploit for CVE-2026-64564 became available, demonstrating container escape and host-root compromise from an unprivileged container under certain conditions. The write-up says the exploit chain abuses the SCTP use-after-free, leaks a kernel address, and launches a process in the host namespaces outside the container boundary.
Jun Yang authored, and Jakub Kicinski committed, upstream Linux kernel commit 9b2854f86f0b to block DEL-IP from deleting the transport currently referenced by ASCONF processing, fixing the SCTP use-after-free later tracked as CVE-2026-64564. The patch was also copied to stable@kernel.org for backporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcelinuxsecurity.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourcelore.kernel.org
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.