Vulnerability in Linux Kernel's SCTP Handling Can Lead to Memory Issues
CVE-2026-64564

9.8CRITICAL

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 August 2026

Badges

📈 Trended📈 Score: 3,320👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-64564?

CVE-2026-64564 is a vulnerability found in the Linux Kernel's handling of Stream Control Transmission Protocol (SCTP). This protocol is critical for enabling modern networking features, particularly in telecom and cloud environments where it facilitates message-oriented communication between systems. The specific vulnerability pertains to an improper handling of Address Parameter Procedures within SCTP's ASCONF (Address Configuration) mechanism. Malicious actors can exploit this flaw to trigger memory-related issues, potentially causing system instability and unauthorized access to system resources when the kernel attempts to dereference freed memory. This can adversely impact organizations relying on Linux systems for critical applications, leading to unexpected crashes and disruption of service, as well as potential data integrity issues.

Potential impact of CVE-2026-64564

  1. System Instability: Exploitation of this vulnerability can lead to severe memory management errors, potentially causing crashes or freezes in systems that rely upon the Linux kernel's SCTP functionality, leading to interruptions in services and loss of productivity.

  2. Data Integrity Risks: With the risk of unauthorized access to memory areas, compromised data integrity could occur. This might allow adversaries to manipulate or extract sensitive information, leading to data breaches and critical security incidents.

  3. Increased Attack Surface: Organizations that utilize SCTP in their network designs may find themselves more vulnerable due to this flaw. Failure to address this vulnerability could result in an increase in the potential for sophisticated attacks leveraging memory exploits, thereby heightening the risk profile of affected systems.

Affected Version(s)

Linux 42e30bf3463cd37d73839376662cb79b4d5c416c

Linux 42e30bf3463cd37d73839376662cb79b4d5c416c

Linux 42e30bf3463cd37d73839376662cb79b4d5c416c < 2b324ba3494ae958cba16a453e3e71489b4de7fc

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers - SwapUpdate

Swati KhandelwalAug 07, 2026Linux / Vulnerability

2 weeks ago

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers - IT Security News

2026-08-08 11:08 SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address...

2 weeks ago

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host - IT Security News

2026-08-07 21:08 A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and...

3 weeks ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.