<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SCTP on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/sctp/</link><description>Recent content in SCTP on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 10 Aug 2026 12:43:52 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/sctp/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux Kernel SCTP Flaw Let Local Users Gain Root for 18 Years</title><link>https://hackingpassion.com/sctphantom-linux-kernel-sctp-root/</link><pubDate>Mon, 10 Aug 2026 12:43:52 +0200</pubDate><guid>https://hackingpassion.com/sctphantom-linux-kernel-sctp-root/</guid><description>&lt;p>An AI found a hole in the Linux kernel that sat open for 18 years, then wrote the exploit that turns a local user into root. The machines were not misconfigured. The bug was in the kernel itself, since 2007. 🧐&lt;/p>
&lt;p>Researchers at Tencent&amp;rsquo;s Zhuque Lab published the full analysis on 6 August. They track it as &lt;strong>CVE-2026-64564&lt;/strong> and named it &lt;strong>SCTPhantom&lt;/strong>. It lets a normal user on a Linux machine climb all the way to root, and from inside a container it can break out onto the host underneath. The code that made this possible went in during December 2007. It reached users with kernel 2.6.25 in April 2008, and has been in the kernel ever since. The fix landed at the start of August. That is eighteen years of a flaw sitting in a file few people ever open. It could not have been used this way in 2008, though. The path to root Tencent built relies on kernel machinery that did not exist yet.&lt;/p></description></item></channel></rss>