vulnerability
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
High
Summary
A 18-year-old vulnerability in Linux's SCTP networking code allows local users to gain root access on a host, potentially escaping containers. Tencent researchers discovered and demonstrated this flaw, which has existed since 2008, and a related vulnerability was patched just days before. While no public exploit code exists, the researchers successfully demonstrated a container escape using a specific configuration and a tool developed by Corvus AI.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
