news
New Debian 13 Kernel Security Update Fixes “Zapscape” and “SCTPhantom”
The new Debian 13 “Trixie” kernel update addresses a total of 28 flaws, a smaller number compared to the 68 vulnerabilities patched in last week’s kernel security update. These new Linux kernel vulnerabilities may lead to privilege escalation, denial of service, or information leaks.
The most important one in this update is CVE-2026-64564, a.k.a. “SCTPhantom,” an 18-year-old use-after-free in the kernel’s SCTP ASCONF handling that lets a local unprivileged user get root and escape containers.