18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
Overview
A long-standing vulnerability in the Linux SCTP networking code, present since 2008, has been discovered to allow local users to gain root access on the host system. Tencent researchers demonstrated that this use-after-free bug could enable an attacker to escape from a container and access the underlying machine. This issue affects users running older Linux kernels that have SCTP enabled. Fortunately, patches have been released for multiple stable kernel versions, including 7.1.6 and 6.6.148, as of August 3. It's crucial for anyone using affected kernels to update promptly to prevent potential exploitation.
Key Takeaways
- Affected Systems: Linux kernels with SCTP enabled, specifically versions prior to 7.1.6, 6.18.42, 6.12.101, and 6.6.148
- Action Required: Update to stable kernels 7.
- Timeline: Ongoing since 2008
Original Article Summary
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.
Impact
Linux kernels with SCTP enabled, specifically versions prior to 7.1.6, 6.18.42, 6.12.101, and 6.6.148
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Ongoing since 2008
Remediation
Update to stable kernels 7.1.6, 6.18.42, 6.12.101, or 6.6.148, released on August 3
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Linux, Vulnerability, Update.