Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
The Hacker News
3 days ago

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

By info@thehackernews.com (The Hacker News)

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.