Kernel maintainers achieve coordinated disclosure with fixes pre-deployed
1Sep 18 3:00 AM · 6d ago · 3 posts · 2 sources · development 1 of 3
Patches from kernel maintainers Stefan Klassert, Xin Long, Paolo Abeni, Willem de Bruijn, and Greg KH landed over preceding weeks before public disclosure, enabling system owners to apply fixes immediately upon publication.
linux,security
“The underlying bugs have been around for 10-21 years. The first three LPEs require unprivileged user namespaces; DiagSpill does not.”
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel: - DirtyAH6 (CVE-2026-80844) - TUNderflow (CVE-2026-81000) - PPPoEject (CVE-2026-68121) - DiagSpill (CVE-2026-74469) "The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or…
Linux kernel root exploits in EH6, SCTP, PPPoE: https:// seclists.org/oss-sec/2026/q3/8 22 If you don't know what these abbreviations means: networking stuff that you probably don't use (ok, you may use PPPoE on your Internet router, but you still don't need it on your desktop or server). I'll add my ceterum censeo: Attack surface reduction works…