CYBERSECURITYTRACKER
TRACKING7,256 stories in this site build1,517 vulnerability news stories in this site build
Permanent story citation

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4056

As cited

Copy frozen at (site build).

vulnerabilities

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free vulnerability in Linux's SCTP networking subsystem, present since 2008, allows local users to gain root privileges and break out of containers. The vulnerability was patched in stable kernel versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148 released on August 3.

Why it matters: Container operators and Linux administrators running older kernels with SCTP enabled face privilege escalation and container escape risks; immediate kernel patching is required for affected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

Researchers at Tencent identified a use-after-free vulnerability in Linux's Stream Control Transmission Protocol (SCTP) code that could allow local users to gain root privileges and escape containers. The flaw, present since 2008, was addressed in kernel updates released on August 3, 2026. Systems running unpatched kernels with SCTP enabled remain exposed.

Why it matters: Linux administrators and containerized environments using kernels older than 7.1.6, 6.18.42, 6.12.101, or 6.6.148 must patch immediately to prevent privilege escalation and container escape.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary