Build credibility. Find opportunity. Advance in cybersecurity.
Font size: +

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

At a glance

  • A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Sign in to read full story
In order for you to continue reading the full contents of the post, you will need to login first

Copyright

© SecurityTalent.com — original summary and analysis

3.8 Million Impacted by Unlimited Technology Syste...

Related Posts

 

Comments

Already Registered? Login Here
No comments made yet. Be the first to submit a comment