On Thu Aug 6, 2026 at 12:33 PM BST, Fourie Zhang wrote: > Hi all, > > We are publishing details of SCTPhantom, CVE-2026-64564, a use-after-free > in Linux SCTP Dynamic Address Reconfiguration. > > Impact: > - Local low-privileged user -> root on affected systems. > - Container -> host root.
I notice there is no mitigation section in the write up. Can you confirm if unloading / blacklisting the sctp module - on a system where this isn't built into the kernel - would protect against this exploit. Thanks, Emily
