
18-year-old Linux SCTP flaw could allow root access and container escape
Security researchers have disclosed an 18-year-old use-after-free vulnerability in the Linux kernel’s SCTP networking implementation that can allow a local attacker to escalate privileges to root and, in some configurations, escape a container. The flaw has existed since SCTP code was introduced in 2008 and becomes exploitable when the SCTP module is available to an attacker. Tencent researchers reported the issue, and fixes have been released in updated Linux kernel branches. Administrators are advised to apply patched kernels or disable SCTP where it is not required.