18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.

The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Lessons Learned from CISA’s Recent GitHub Leak

Lessons Learned from CISA’s Recent GitHub Leak The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal

Loupe – A iOS app that raises awareness about what native apps can see

Loupe – A iOS app that raises awareness about what native apps can see Source: Hacker News

Four Time Scales for Technology Development and Deployment

Four Time Scales for Technology Development and Deployment Source: Hacker News