SECURITY·중요도 8·2026. 08. 07.·The Hacker News

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

── KO ──────────────────

리눅스의 SCTP 버그가 컨테이너를 탈출해 루트 권한을 획득할 수 있다는 경고.

리눅스의 SCTP 네트워킹 코드에서 발견된 사용 후 해제(use-after-free) 버그가 로컬 사용자가 루트 권한을 획득하면서 호스트 시스템에 접근할 수 있게 할 수 있다는 보고가 있다. 이 결함은 2008년부터 존재해왔으며, 관련 패치가 최근 안정 커널 버전 7.1.6, 6.18.42, 6.12.101 및 6.6.148에 포함되어 배포되었다. SCTP가 접근 가능한 구 버전의 커널을 사용하는 경우 즉시 업데이트해야 한다.


── EN ──────────────────

Linux SCTP bug allows local users to gain root and escape containers.

A use-after-free bug in Linux's SCTP networking code allows local users to gain full root access on the host system, potentially escaping from containers. This flaw has existed since 2008, and recent patches have been included in stable kernel updates 7.1.6, 6.18.42, 6.12.101, and 6.6.148. Users running older kernels with accessible SCTP are urged to update immediately.

원문 보기 →목록으로