Description:
Multiple elevation of privilege vulnerabilities ("Zapscape" and "SCTPhantom") are found in the Linux Kernel. For the Zapscape, this vulnerability could allow an attacker with root access inside a vulnerable guest VM to exploit KVM’s use-after-free flaw to escape the VM and gain root access to the host. For the SCTPhantom, this vulnerability could allow a low-privileged local attacker to exploit a use-after-free flaw in the Linux SCTP implementation to gain root privileges and potentially escape a vulnerable container to access the host.
Reports indicated that proof-of-concept (PoC) exploit code for an elevation of privilege vulnerability (Zapscape, CVE-2026-64561) is publicly available and it is at high risk of exploitation. System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Affected Systems:
Zapscape, CVE-2026-64561
Linux kernel versions 5.9 through 6.6.148 (excluding 6.6.148)
Linux kernel versions 6.7 through 6.12.101 (excluding 6.12.101)
Linux kernel versions 6.13 through 6.18.42 (excluding 6.18.42)
Linux kernel versions 6.19 through 7.1.6 (excluding 7.1.6)
Linux kernel versions 7.2 through 7.2-rc5 (excluding 7.2-rc5)
SCTPhantom, CVE-2026-64564
Linux kernel versions 2.6.25 through 6.6.148 (excluding 6.6.148)
Linux kernel versions 6.7 through 6.12.101 (excluding 6.12.101)
Linux kernel versions 6.13 through 6.18.42 (excluding 6.18.42)
Linux kernel versions 6.19 through 7.1.6 (excluding 7.1.6)
Linux kernel versions 7.2 through 7.2-rc5 (excluding 7.2-rc5)
Impact:
Successful exploitation of the vulnerabilities could lead to elevation of privilege or security restriction bypass on an affected system.
Recommendation:
The vulnerabilities are fixed in some of the affected Linux distributions including Debian, Red Hat, SUSE and Ubuntu. The following is only a sample list of Linux distributions that are affected. The list is not exhaustive and it is strongly recommended to consult the product vendors if the used Linux systems are affected. System administrators should check with their product vendors to confirm if their Linux systems are affected and the availability of patches, and if so, apply the patches or follow the recommendations provided by the product vendors to mitigate the risk.
Debian
https://security-tracker.debian.org/tracker/CVE-2026-64561
Debian
https://security-tracker.debian.org/tracker/CVE-2026-64564
Red Hat
https://access.redhat.com/security/cve/cve-2026-64561
Red Hat
https://access.redhat.com/security/cve/cve-2026-64564
SUSE
https://www.suse.com/security/cve/CVE-2026-64561.html
SUSE
https://www.suse.com/security/cve/CVE-2026-64564.html
Ubuntu
https://ubuntu.com/security/CVE-2026-64561
Ubuntu
https://ubuntu.com/security/CVE-2026-64564
More Information:
- https://security-tracker.debian.org/tracker/CVE-2026-64561
- https://security-tracker.debian.org/tracker/CVE-2026-64564
- https://access.redhat.com/security/cve/cve-2026-64561
- https://access.redhat.com/security/cve/cve-2026-64564
- https://www.suse.com/security/cve/CVE-2026-64561.html
- https://www.suse.com/security/cve/CVE-2026-64564.html
- https://ubuntu.com/security/CVE-2026-64561
- https://ubuntu.com/security/CVE-2026-64564
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64561
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-64564