conv.

All stories
SecurityQuiet 2d · day 6

Four Linux kernel local root vulnerabilities disclosed with patches ready

DirtyAH6, TUNderflow, PPPoEject, and DiagSpill — bugs 10-21 years old — fixed before public disclosure.

What to know

  • Four local privilege escalation vulnerabilities in the Linux kernel—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—were disclosed on September 18 with patches already available, having been reported under coordinated embargo in mid-July.
  • The bugs have existed for 10-21 years; three require unprivileged user namespaces or specific capabilities, but DiagSpill and DirtyAH6 are remotely exploitable under specific circumstances, with DirtyAH6 theoretically groomable to remote root.
  • CISA has warned that these vulnerabilities are actively being exploited in the wild, prompting system administrators to prioritize patching.
  • The successful coordinated disclosure process—with fixes pre-deployed before public announcement—contradicts prior claims that such coordination was impractical in kernel development.

The dispute Whether the disclosure process represents a genuine improvement in kernel security practices or is an outlier that does not reflect typical coordination challenges. · positions read across 12 posts and comments

most voices

The coordinated disclosure process demonstrates that kernel developers can manage security embargoes effectively, contradicting prior skepticism.

  • “Linux kernel vulnerabilities with proper embargoes and all fixed versions available by the time the issue is made public? Didn't Greg K-H say it couldn't be done?”

    mxey · Lobsters ↗
some voices

The technical achievement is notable—attackers will likely study these vulnerabilities for years to come, and remote exploitation scenarios warrant serious attention.

  • “Wow. I hope that in a few years I'll stumble upon a blog post about someone actually successfully exploiting this :p”

    dzwdz · Lobsters ↗

Security researchers Vulnerability discoverersStefan Klassert, Xin Long, Paolo Abeni, Willem de Bruijn, Greg KH Kernel maintainersCISA U.S. cybersecurity agency

Four Linux kernel local root vulnerabilities disclosed with patches ready
linux,security

How it unfolded 3 developments, newest first · click a bar or a number to jump articlespostscomments

Peak 5 pieces in two hours at Sep 19, 2 PM; 21 pieces over 6 days (5 articles · 11 posts · 5 comments) Sep 18, 2 AM — 3 pieces · 3 posts — Mastodon 2, Lobsters 1Sep 18, 4 AM — quietSep 18, 6 AM — 1 piece · 1 comment — Lobsters 1Sep 18, 8 AM — 2 pieces · 1 post · 1 comment — Hacker News 1, Lobsters 1Sep 18, 10 AM — quietSep 18, 12 PM — quietSep 18, 2 PM — 1 piece · 1 post — Mastodon 1Sep 18, 4 PM — quietSep 18, 6 PM — quietSep 18, 8 PM — 1 piece · 1 comment — Lobsters 1Sep 18, 10 PM — 1 piece · 1 post — Mastodon 1Sep 19, 12 AM — 1 piece · 1 comment — Lobsters 1Sep 19, 2 AM — 1 piece · 1 comment — Lobsters 1Sep 19, 4 AM — quietSep 19, 6 AM — quietSep 19, 8 AM — quietSep 19, 10 AM — quietSep 19, 12 PM — quietSep 19, 2 PM — 5 pieces · 4 articles · 1 post — Google News 4, Mastodon 1Sep 19, 4 PM — quietSep 19, 6 PM — quietSep 19, 8 PM — quietSep 19, 10 PM — quietSep 20, 12 AM — quietSep 20, 2 AM — quietSep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — quietSep 20, 10 AM — quietSep 20, 12 PM — quietSep 20, 2 PM — quietSep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — quietSep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — 1 piece · 1 article — Newswires 1Sep 21, 6 AM — quietSep 21, 8 AM — quietSep 21, 10 AM — quietSep 21, 12 PM — quietSep 21, 2 PM — 1 piece · 1 post — Mastodon 1Sep 21, 4 PM — 2 pieces · 2 posts — Mastodon 2Sep 21, 6 PM — quietSep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — 1 piece · 1 post — Mastodon 1Sep 22, 2 AM — quietSep 22, 4 AM — quietSep 22, 6 AM — quietSep 22, 8 AM — quietSep 22, 10 AM — quietSep 22, 12 PM — quietSep 22, 2 PM — quietSep 22, 4 PM — quietSep 22, 6 PM — quietSep 22, 8 PM — quietSep 22, 10 PM — quietYesterday, 12 AM — quietYesterday, 2 AM — quietYesterday, 4 AM — quietYesterday, 6 AM — quietYesterday, 8 AM — quietYesterday, 10 AM — quietYesterday, 12 PM — quietYesterday, 2 PM — quietYesterday, 4 PM — quietYesterday, 6 PM — quietYesterday, 8 PM — quietYesterday, 10 PM — quietToday, 12 AM — quietToday, 2 AM — quiet 123
Sep 19Sep 20Sep 21Sep 22yesterdaynow · 4:44 AM ET
  1. 3

    CISA warns of active exploitation of Linux kernel vulnerabilities

    CISA issued warnings flagging the three vulnerabilities as being actively exploited in the wild, with coverage from multiple security news outlets.

    1. 3 outlets first by The Hacker News, 4d ago · also CyberSecurityNews, SecurityWeek · read ↗

    • A lot of stuff only gets illegal when you are served paperwork in advance. Stable targetable entities are more vulnerable to it than one-off research announcements.

      k749gtnc9l3wlinux,security5d ago1▲view on Lobsters ↗
    2 more of the top 3 · 6 posts in this stretch
    • ottoto2017@prattohome.com

      「CISAは、Linuxカーネルの3つの脆弱性が悪用されていることを警告した。」: # BLEEPINGCOMPUTER 「米国のサイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、ハッカーがLinuxカーネルの3つの脆弱性を悪用していると警告しており、そのうち1つは重大な脆弱性と評価されている。 これら3つのセキュリティ問題は先週それぞれ別々に報告され、深刻度は中程度から重大までとなっている。そのうちの1つ、CVE-2025-39964として追跡されているものは、Linuxカーネルに14年間存在していた。 CISAはこれら3つの脆弱性を連邦政府機関にとって最優先事項と位置付け、本日中に利用可能なセキュリティアップデートと対策を適用するよう命じた。 」…

      ottoto2017@prattohome.comMastodon2d agoview on Mastodon ↗
    • He said something about it being illegal to not immediately share everything.

      mxeylinux,security5d ago1▲view on Lobsters ↗
    all of them →
  2. 2

    Community notes coordination process contradicts prior kernel developer claims

    Lobsters commenters noted that the successful coordinated embargo and pre-deployment of fixes contradicts earlier statements by Greg K-H that such a process was impractical for kernel development.

    “Linux kernel vulnerabilities with proper embargoes and all fixed versions available by the time the issue is made public? Didn't Greg K-H say it couldn't be done?”
    — mxey
    • > If the target is acting as an IPv6 router/gateway and adds AH in transport mode, the bug can be turned into a remote crash/DoS. With on-target memory grooming, I was able to turn it into remote root in a lab environment. > > Remote-only grooming to root is theoretically possible, but looks extremely difficult. Wow. I hope that in a few years…

      dzwdzlinux,security5d ago2▲view on Lobsters ↗
    2 more of the top 3 · 4 posts in this stretch
    • sambowne@infosec.exchange

      Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root https:// thehackernews.com/2026/09/publ ic-exploits-released-for-four-linux.html

      sambowne@infosec.exchangeMastodon5d agoview on Mastodon ↗
    • He said it couldn't be done _by core Linux developers_, and also what happened here (fixes quitely merged into public branches over the past few weeks before security writeup going public) is what he was asked to improve upon when saying that kernel devs can't do better than that.

      k749gtnc9l3wlinux,security5d ago2▲view on Lobsters ↗
    all of them →
  3. 1

    Kernel maintainers achieve coordinated disclosure with fixes pre-deployed

    Patches from kernel maintainers Stefan Klassert, Xin Long, Paolo Abeni, Willem de Bruijn, and Greg KH landed over preceding weeks before public disclosure, enabling system owners to apply fixes immediately upon publication.

    “The underlying bugs have been around for 10-21 years. The first three LPEs require unprivileged user namespaces; DiagSpill does not.”
    — Security researcher · source
    • harrysintonen

      It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel: - DirtyAH6 (CVE-2026-80844) - TUNderflow (CVE-2026-81000) - PPPoEject (CVE-2026-68121) - DiagSpill (CVE-2026-74469) "The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or…

      harrysintonenMastodon6d ago40▲view on Mastodon ↗
    1 more of the top 2 · 2 posts in this stretch
    • hanno@mastodon.social

      Linux kernel root exploits in EH6, SCTP, PPPoE: https:// seclists.org/oss-sec/2026/q3/8 22 If you don't know what these abbreviations means: networking stuff that you probably don't use (ok, you may use PPPoE on your Internet router, but you still don't need it on your desktop or server). I'll add my ceterum censeo: Attack surface reduction works…

      hanno@mastodon.socialMastodon6d agoview on Mastodon ↗
    all of them →
  4. background

    DirtyAH6, TUNderflow, PPPoEject, and DiagSpill vulnerabilities publicly disclosed — The four vulnerabilities (CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, CVE-2026-74469) were published with technical writeups and proof-of-concepts. The bugs have been in the kernel for 10-21 years; the first three require unprivileged user namespaces or specific capabilities, while DiagSpill does not. Two are remotely exploitable under specific circumstances.

  5. background

    Security researchers report four kernel vulnerabilities to linux-kernel security team — Four local privilege escalation bugs affecting IPv6 AH, TUN/TAP, PPPoE, and SCTP subsystems were reported to security@kernel.org mid-July under coordinated embargo with linux-distros@.

What people are saying 3 voices from 1 site · best of 12 · verbatim