- What: Security update for Proxmox VE addresses use-after-free vulnerability
- Impact: Could allow local privilege escalation
ProxmoxSecurityAdvisory Proxmox Staff Member Staff member Jan 1, 2024 100 0 26 Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue​ Advisory date : 2026-08-10 Packages : proxmox-kernel-* Details : A use-after-free issue in the Linux kernels SCTP code allowed a unprivileged local attacker to obtain root privileges, and potentially escape from unprivileged containers. Mitigations : Preventing the sctp module from being loaded mitigates the issue. Fixed in : - proxmox-kernel-7.0.14-10-pve(-signed) (Trixie based products) - proxmox-kernel-6.8.12-41-pve(-signed) (Bookworm based products) References : - CVE-2026-64564 - https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564