<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>SCTPhantom | OKHK 👀</title><description>(⁠◔⁠‿⁠◔⁠) Are you OK？✨ Thinking...</description><link>https://tg.okhk.net</link><item><title>🔴 Linux 内核 sctp 模块本地提权漏洞 SCTPhantom</title><link>https://tg.okhk.net/posts/10754</link><guid isPermaLink="true">https://tg.okhk.net/posts/10754</guid><pubDate>Fri, 07 Aug 2026 07:56:10 GMT</pubDate><content:encoded>&lt;div class=&quot;tgme_widget_message_forwarded_from accent_color&quot;&gt;Forwarded from &lt;a class=&quot;tgme_widget_message_forwarded_from_name&quot; href=&quot;https://t.me/outvivid/4895&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;span&gt;层叠 - The Cascading&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;i class=&quot;emoji&quot;&gt;&lt;b&gt;&lt;span class=&quot;post-title-source&quot;&gt;🔴&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;span class=&quot;post-title-source&quot;&gt; Linux 内核 sctp 模块本地提权漏洞 &lt;/span&gt;&lt;mark class=&quot;highlight&quot;&gt;&lt;span class=&quot;post-title-source&quot;&gt;SCTPhantom&lt;/span&gt;&lt;/mark&gt;&lt;span class=&quot;post-title-source&quot;&gt;。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。&lt;br /&gt;- Kernel 上游和 Debian Trixie/Sid 已经发布修复版本。&lt;br /&gt;&lt;br /&gt;CVE: CVE-2026-64564&lt;br /&gt;CVSS: 8.5 （作者自评）&lt;br /&gt;Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://matrix.tencent.com/zh/2026/08/06/sctphantom-CVE-2026-64564&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;matrix.tencent.com/~&quot;&gt;matrix.tencent.com/~&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[感谢一位匿名订户提供信息。]&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/result?q=%23SCTPhantom&quot; title=&quot;#SCTPhantom&quot;&gt;#SCTPhantom&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Kernel&quot; title=&quot;#Kernel&quot;&gt;#Kernel&lt;/a&gt;&lt;a class=&quot;tgme_widget_message_link_preview&quot; href=&quot;https://matrix.tencent.com/zh/2026/08/06/sctphantom-CVE-2026-64564&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;SCTPhantom 是 Linux 内核 SCTP 动态地址重配置功能中的一个释放后使用漏洞。&quot;&gt;
  
  &lt;div class=&quot;link_preview_site_name accent_color&quot;&gt;腾讯朱雀实验室&lt;/div&gt;
  &lt;img class=&quot;link_preview_image&quot; alt=&quot;SCTPhantom: 潜伏18年的Linux内核提权与容器逃逸漏洞 · 腾讯朱雀实验室&quot; src=&quot;/static/https://cdn4.telesco.pe/file/DjyW_1Wexx1bxMDW61-TDMmdBJqzmv3PKhfaGjByKLWyVHacOZ8oqyjBT4VgmFJMtqw-qtyfc7PjP1Fq0VIgh2ZQi5eaPX9TC8fvwRvbXy6TyjmFVCJ-xi6LNTnTTvib6Fzn9x133P-RiXQzGXmk3UTiZVKlezFStOVlS1lGdb0kkuVl2oDjyZwJ7uckwwoZerToAy2oOdcIO44q4KG7SjJHNLiU_bDc90ipNWLVy6XCl98p9Yi3Ewp82Nh-okHRd3bO1yOuis4PREeWOf6O-vrbnBuEcLzqHCGy_nwt-TB4NaoDxQ2zPMqa-BB8Wc3BZu3HP81bMZIBPbCGz7lEbg.jpg&quot; width=&quot;1200&quot; height=&quot;630&quot; loading=&quot;eager&quot; /&gt;
  &lt;div class=&quot;link_preview_title&quot;&gt;&lt;mark class=&quot;highlight&quot;&gt;SCTPhantom&lt;/mark&gt;: 潜伏18年的Linux内核提权与容器逃逸漏洞 · 腾讯朱雀实验室&lt;/div&gt;
  &lt;div class=&quot;link_preview_description&quot;&gt;&lt;mark class=&quot;highlight&quot;&gt;SCTPhantom&lt;/mark&gt; 是 Linux 内核 SCTP 动态地址重配置功能中的一个释放后使用漏洞。&lt;/div&gt;
&lt;/a&gt;</content:encoded></item></channel></rss>