- Sources: primary, discussion
- Summary: Tencent Zhuque Lab published a use-after-free in the Linux SCTP implementation, rated CVSS v4.0 8.5, from a bug present since Linux 2.6.25. The lab reports local root on Debian 13, Ubuntu 24.04, Rocky Linux 9 and OpenCloudOS, plus container escape in six of eight attempts without CAP_NET_ADMIN or CAP_SYS_ADMIN. First fixed versions are 6.6.148, 6.12.101, 6.18.42, 7.1.6 and mainline 7.2-rc5.
- Why it matters: An unprivileged local process on an unpatched multi-tenant host reaches root and, in most reported attempts, the host from inside a container.
send feedback on this story