#asknostr
can the real Ian Coleman please stand up?
View quoted note →
Cat-Go-Purrrrrrr
npub1jj9u...nhpx
cat_go_purrrrrrr@minibits.cash
another week another kernel bug patched
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
TL;DR: SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references.
Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems.
The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b.
...
Linux 7.2-rc2
OpenCloudOS-family target
Debian 13
Rocky Linux 9 / RHEL 9
Ubuntu 24.04 6.8.0-134-generic
// Root
These results also provide a basis for assessing the impact. Under the CVSS v4.0 base metrics, the vulnerability is rated as follows:
CVSS v4.0 Base Score (CVSS-B): 8.5 (High)


Tencent Zhuque Lab
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab
SCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
yoooooo this is dope - new #defcon badge got the bunnie huang's Baochip - #SoC #secure #element
"Baochip-1x, a mostly-open, full-custom silicon chip fabricated in TSMC 22nm, targeted at high assurance applications. It’s a security chip, but far more open than any other security chip; it’s also a general purpose microcontroller that fills a gap in between the Raspberry Pi RP2350 (found on the Pi Pico2) and the NXP iMXRT1062 (found on the Teensy 4.1)."
View quoted note →
Baochip-1x: A Mostly-Open, 22nm SoC for High Assurance Applications « bunnie's blog
lulz 
