CyberSecurity News
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
AI summary
A vulnerability in Linux's SCTP networking code, present since 2008, can be exploited by local users to gain root access on a host. This flaw also allows attackers to escape containers and access the underlying machine. Researchers at Tencent demonstrated this capability. The issue is a use-after-free bug that can be leveraged to achieve full root access. A fix for the vulnerability has been released in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148. Users running older kernels with accessible SCTP should update to a patched version.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

