SCTPhantom
We are aware of the high profile ‘SCTPhantom’ exploit which impacts the Linux kernel.
It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance. The impacted kernel modules are also not loaded by default within the VQCM VM and by default are blacklisted in the kernel.
As such there should be no need for action to mitigate unless customers have specifically enabled this module. If customers are unsure or if you have any questions about this CVE, please email security@vqcomms.com

