FR
live
Linux High CVSS 7.8

Four public exploits turn an ordinary Linux account into root, through bugs up to 21 years old

On 18 September 2026, researcher Asim Manizada published working exploits for four Linux kernel flaws — DirtyAH6, TUNderflow, PPPoEject and DiagSpill — each of which gives root to any local user. The fixes have been available for weeks, so check your kernel version and restrict unprivileged user namespaces now.

A concrete emergency stairwell in near darkness, one single stair step glowing amber as the only lit tread on the climb.

18 September 2026, 06:00 UTC. Researcher Asim Viladi Oglu Manizada publishes four working exploits for the Linux kernel, each turning an ordinary local account into root. Mid-July 2026. He had reported all four flaws to the kernel security team, which fixed them through coordinated disclosure. September 2026. The bugs being exploited are between 10 and 21 years old. Why it matters: the fixes already exist in the stable branches, but publication changes the calculus — code that was a theoretical demonstration becomes a ready-made tool for anyone who already has a foot on the machine.

Four flaws, four paths to root

The quartet carries baptismal names — DirtyAH6, TUNderflow, PPPoEject, DiagSpill — and each targets an old networking component of the kernel. Their common thread is more telling than their differences: three of the four require unprivileged user namespaces, the feature that lets a right-less user obtain a semblance of root inside an isolated container, and which has become the escalation vector of choice in recent years.

DirtyAH6 (CVE-2026-80844) hits the IPv6 Authentication Header handling in the IPsec/XFRM code. When the kernel processes a malformed IPv6 routing header without correctly validating the segments_left field, an internal pointer can move outside the intended memory area and trigger an out-of-bounds operation. It is primarily a local privilege escalation, but a system acting as an IPv6 router that uses AH in transport mode could face remote denial of service under narrow conditions.

TUNderflow (CVE-2026-81000) lives in the TUN/TAP virtual network-device subsystem. A malicious local user can pass oversized receive-headroom values through specific network-device configurations — including Open vSwitch paths — and trigger an integer underflow during socket-buffer allocation, placing packet data outside its allocated area and opening out-of-bounds reads and writes.

PPPoEject (CVE-2026-68121) is a use-after-free in the kernel’s PPP over Ethernet implementation. The pppoe_sendmsg() function holds a pointer to a PPPoE header while calling a lower-level function that can reallocate the socket buffer and invalidate that pointer. Later writes through the stale pointer can corrupt freed kernel memory.

DiagSpill (CVE-2026-74469) is the most remarkable of the four, because it requires neither unprivileged user namespaces nor special capabilities as long as SCTP and sctp_diag are available. An SCTP association can hold up to 65,536 peer transports, while the related counter is only 16 bits wide. When the count reaches the limit, it wraps to zero, and the diagnostic code reserves too little space before copying peer information — the resulting overwrite spills far beyond the Netlink response buffer.

Why user namespaces are the real common denominator

The most important signal in this publication is not the list of components — IPv6, TUN/TAP, PPPoE, SCTP — but the reliance of three of the four exploits on unprivileged user namespaces. That feature, designed to isolate unprivileged containers, has become the standard bridge between «an ordinary user account» and «control of the kernel».

The mechanics are simple to follow. An unprivileged user namespace lets a right-less user create an environment in which they are UID 0, with root capabilities — but confined to that namespace. Kernel flaws then become exploitable from this local fake root, which requires no real privileged access at all. That is exactly what DirtyAH6, TUNderflow and PPPoEject do: they rely on the ability to create or control suitable network namespaces.

DiagSpill breaks the pattern. It does not depend on user namespaces, which means disabling unprivileged user namespaces does not neutralize it. That is the nuance that matters for defenders: the classic reflex of «flip kernel.unprivileged_userns_clone and sleep easy» covers only part of the quartet.

The fix already exists; the risk lives elsewhere

All four flaws are already fixed in the stable branches. The first versions to contain the complete set of patches are Linux 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4. The publication of the exploits therefore does not reveal a zero-day: it lowers the exploitation cost for systems that have not yet been updated.

That is exactly where the risk concentrates. A server still running an unpatched 6.1 or 6.6 kernel — often out of inertia, because the reboot is costly or planned quarterly — becomes a target whose exploitation is already written and public. The distance between «flaw fixed upstream» and «machine actually protected» is measured in weeks of patch lag, not in the absence of a fix.

The attack vector is also the one that makes escalation most dangerous: local access. An attacker who has obtained a user account — through phishing, a compromised web service, a password leak — now has four documented paths to root. In a datacenter or a multi-tenant cloud, that is the difference between «one more user is compromised» and «the whole machine belongs to the attacker».

What to do, in order

Three actions suffice, and they are cumulative rather than alternative.

Update the kernel. This is the only measure that covers all four flaws, DiagSpill included. Check your version with uname -r and compare it against the patched branches. For most distributions, a security update is already available in the official repositories.

Restrict unprivileged user namespaces. On systems where an update is not immediate, disabling kernel.unprivileged_userns_clone (or the distribution equivalent) neutralizes DirtyAH6, TUNderflow and PPPoEject. Caveat: this breaks some unprivileged containers, and does not protect against DiagSpill.

Disable unused components. AH6, TUN/TAP, PPPoE and SCTP/sctp_diag are often present by default without being used. Removing or disabling them shrinks the attack surface — but, like user namespaces, this is not a substitute for a kernel update.

bash
uname -r
# compare against the patched branches: 5.10.270, 5.15.221, 6.1.188,
# 6.6.157, 6.12.109, 6.18.50, 7.2.4
sysctl kernel.unprivileged_userns_clone=0   # neutralizes 3 of 4 exploits

Verdict

If you manage servers or multi-user machines, treat this publication as a patch deadline, not a researcher’s curiosity: the fixes have existed for weeks, and the exploit code is now public. If your fleet still runs unpatched 6.1 or 6.6 kernels, move the update to the front of the queue — a reboot costs less than handing root to an attacker who already has an account. If you cannot patch today, disable unprivileged user namespaces and turn off the unused networking components, keeping in mind that DiagSpill requires the full fix. The lesson of this quartet is clear: in a decades-old kernel, the legacy networking code is a deposit of escalations waiting for someone to document them — the only durable defense is the freshness of the version you actually run.

References

cve

Linked vulnerabilities

CVE-2026-81000In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the result becomes negative when stored in good_linear. That value later wraps when assigned to the size_t linear variable, and tun_alloc_skb() can place skb->data outside the allocated head. Bound the headroom stored by TUN to the one-page skb-head budget and the largest non-sentinel 16-bit skb header offset. Leave one linear byte for raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN. Also pull the raw-TUN protocol byte and the TAP Ethernet header before accessing them, so these checks remain safe for nonlinear skbs supplied by other allocation paths. High CVSS 7.8 11/09 CVE-2026-74469In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail. Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit. High CVSS 8.8 15/08 CVE-2026-68121In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head. High CVSS 7.8 10/08

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Toolpak wants to do for developer tools what Flatpak did for apps

On 26 September 2026, GNOME developer Jordan Petridis introduced Toolpak, a Flatpak-inspired format for shipping strace, ripgrep, and qemu on image-based systems without breaking them. For anyone working on Silverblue or GNOME OS, it fills the gap immutable distributions never closed.

Linux 7.4 makes hot-adding memory to VMs and CXL up to 81% faster

A patch series by Yuan Liu (Intel), queued in mm/core.git ahead of the Linux 7.4 merge window, replaces page-by-page zone scans with an optimized contiguity check. Measured: up to 81% less time to hot-add memory to a VM and 75% to hot-remove it, with Samsung also reporting CXL gains.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss