Threat Intelligence

Decades-Old Linux Kernel Flaw Lets Attackers Escape Containers and Seize Root Access

The Hacker News · 7 Aug 2026
Key Takeaway If your business runs Linux servers or containers, check your kernel version now and apply the latest security patches to close this critical privilege escalation flaw.

Security researchers at Tencent have uncovered a serious flaw in the Linux kernel's SCTP networking component that has existed undetected since 2008. The bug, known as a 'use-after-free' vulnerability, allows an attacker with local access to a system to escalate their privileges to full root control—the highest level of access on a machine.

What makes this discovery particularly concerning for businesses using cloud infrastructure or containerised applications is that researchers demonstrated the flaw could be used to break out of a container and gain access to the underlying host system. Containers are widely used to isolate applications, so an escape like this undermines a key security boundary many businesses rely on.

The good news is that fixes are already available. Kernel maintainers have released patched versions—7.1.6, 6.18.42, 6.12.101, and 6.6.148—as of August 3. Organisations running Linux systems, particularly those with SCTP networking enabled, should check their kernel version and apply updates as soon as possible to close this long-standing security gap.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.