SCTPhantom, the 18-Year-Old Linux SCTP Flaw That Hands Attackers Root and Breaks Container Isolation
A use-after-free bug in the Linux kernel’s SCTP stack, dormant for 18 years and now tracked as CVE-2026-64564, lets a local attacker escalate to root and escape containers. Patches landed August 4, 2026 — kernel updates are not optional.