Cat-Go-Purrrrrrr's avatar
Cat-Go-Purrrrrrr
npub1jj9u...nhpx
cat_go_purrrrrrr@minibits.cash
another week another kernel bug patched SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free TL;DR: SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b. ... Linux 7.2-rc2 OpenCloudOS-family target Debian 13 Rocky Linux 9 / RHEL 9 Ubuntu 24.04 6.8.0-134-generic // Root These results also provide a basis for assessing the impact. Under the CVSS v4.0 base metrics, the vulnerability is rated as follows: CVSS v4.0 Base Score (CVSS-B): 8.5 (High)
yoooooo this is dope - new #defcon badge got the bunnie huang's Baochip - #SoC #secure #element "Baochip-1x, a mostly-open, full-custom silicon chip fabricated in TSMC 22nm, targeted at high assurance applications. It’s a security chip, but far more open than any other security chip; it’s also a general purpose microcontroller that fills a gap in between the Raspberry Pi RP2350 (found on the Pi Pico2) and the NXP iMXRT1062 (found on the Teensy 4.1)." View quoted note →