Four Linux kernel local root vulnerabilities disclosed with patches ready
DirtyAH6, TUNderflow, PPPoEject, and DiagSpill — bugs 10-21 years old — fixed before public disclosure.
What to know
- Four local privilege escalation vulnerabilities in the Linux kernel—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—were disclosed on September 18 with patches already available, having been reported under coordinated embargo in mid-July.
- The bugs have existed for 10-21 years; three require unprivileged user namespaces or specific capabilities, but DiagSpill and DirtyAH6 are remotely exploitable under specific circumstances, with DirtyAH6 theoretically groomable to remote root.
- CISA has warned that these vulnerabilities are actively being exploited in the wild, prompting system administrators to prioritize patching.
- The successful coordinated disclosure process—with fixes pre-deployed before public announcement—contradicts prior claims that such coordination was impractical in kernel development.
The dispute Whether the disclosure process represents a genuine improvement in kernel security practices or is an outlier that does not reflect typical coordination challenges. · positions read across 12 posts and comments
The coordinated disclosure process demonstrates that kernel developers can manage security embargoes effectively, contradicting prior skepticism.
-
“Linux kernel vulnerabilities with proper embargoes and all fixed versions available by the time the issue is made public? Didn't Greg K-H say it couldn't be done?”
mxey · Lobsters ↗
The technical achievement is notable—attackers will likely study these vulnerabilities for years to come, and remote exploitation scenarios warrant serious attention.
-
“Wow. I hope that in a few years I'll stumble upon a blog post about someone actually successfully exploiting this :p”
dzwdz · Lobsters ↗
Security researchers Vulnerability discoverersStefan Klassert, Xin Long, Paolo Abeni, Willem de Bruijn, Greg KH Kernel maintainersCISA U.S. cybersecurity agency
How it unfolded 3 developments, newest first · click a bar or a number to jump articlespostscomments
-
3
CISA warns of active exploitation of Linux kernel vulnerabilities
CISA issued warnings flagging the three vulnerabilities as being actively exploited in the wild, with coverage from multiple security news outlets.
-
3 outlets first by The Hacker News, 4d ago · also CyberSecurityNews, SecurityWeek · read ↗
-
A lot of stuff only gets illegal when you are served paperwork in advance. Stable targetable entities are more vulnerable to it than one-off research announcements.
2 more of the top 3 · 6 posts in this stretch
-
O
「CISAは、Linuxカーネルの3つの脆弱性が悪用されていることを警告した。」: # BLEEPINGCOMPUTER 「米国のサイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は、ハッカーがLinuxカーネルの3つの脆弱性を悪用していると警告しており、そのうち1つは重大な脆弱性と評価されている。 これら3つのセキュリティ問題は先週それぞれ別々に報告され、深刻度は中程度から重大までとなっている。そのうちの1つ、CVE-2025-39964として追跡されているものは、Linuxカーネルに14年間存在していた。 CISAはこれら3つの脆弱性を連邦政府機関にとって最優先事項と位置付け、本日中に利用可能なセキュリティアップデートと対策を適用するよう命じた。 」…
-
He said something about it being illegal to not immediately share everything.
-
-
2
Community notes coordination process contradicts prior kernel developer claims
Lobsters commenters noted that the successful coordinated embargo and pre-deployment of fixes contradicts earlier statements by Greg K-H that such a process was impractical for kernel development.
“Linux kernel vulnerabilities with proper embargoes and all fixed versions available by the time the issue is made public? Didn't Greg K-H say it couldn't be done?”
— mxey -
> If the target is acting as an IPv6 router/gateway and adds AH in transport mode, the bug can be turned into a remote crash/DoS. With on-target memory grooming, I was able to turn it into remote root in a lab environment. > > Remote-only grooming to root is theoretically possible, but looks extremely difficult. Wow. I hope that in a few years…
2 more of the top 3 · 4 posts in this stretch
-
S
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root https:// thehackernews.com/2026/09/publ ic-exploits-released-for-four-linux.html
-
He said it couldn't be done _by core Linux developers_, and also what happened here (fixes quitely merged into public branches over the past few weeks before security writeup going public) is what he was asked to improve upon when saying that kernel devs can't do better than that.
-
-
1
Kernel maintainers achieve coordinated disclosure with fixes pre-deployed
Patches from kernel maintainers Stefan Klassert, Xin Long, Paolo Abeni, Willem de Bruijn, and Greg KH landed over preceding weeks before public disclosure, enabling system owners to apply fixes immediately upon publication.
“The underlying bugs have been around for 10-21 years. The first three LPEs require unprivileged user namespaces; DiagSpill does not.”
— Security researcher · source -
H
It's Friday, and we have 4 more local privilege escalation vulnerabilities disclosed for the Linux kernel: - DirtyAH6 (CVE-2026-80844) - TUNderflow (CVE-2026-81000) - PPPoEject (CVE-2026-68121) - DiagSpill (CVE-2026-74469) "The underlying bugs have been around for 10-21 years. The first three LPEs require either unprivileged user namespaces or…
1 more of the top 2 · 2 posts in this stretch
-
H
Linux kernel root exploits in EH6, SCTP, PPPoE: https:// seclists.org/oss-sec/2026/q3/8 22 If you don't know what these abbreviations means: networking stuff that you probably don't use (ok, you may use PPPoE on your Internet router, but you still don't need it on your desktop or server). I'll add my ceterum censeo: Attack surface reduction works…
-
-
background
DirtyAH6, TUNderflow, PPPoEject, and DiagSpill vulnerabilities publicly disclosed — The four vulnerabilities (CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, CVE-2026-74469) were published with technical writeups and proof-of-concepts. The bugs have been in the kernel for 10-21 years; the first three require unprivileged user namespaces or specific capabilities, while DiagSpill does not. Two are remotely exploitable under specific circumstances.
-
background
Security researchers report four kernel vulnerabilities to linux-kernel security team — Four local privilege escalation bugs affecting IPv6 AH, TUN/TAP, PPPoE, and SCTP subsystems were reported to security@kernel.org mid-July under coordinated embargo with linux-distros@.
What people are saying 3 voices from 1 site · best of 12 · verbatim
- Sep 21
-
P
CISA alerts of active exploitation of three Linux kernel flaws https://www. bleepingcomputer.com/news/secu rity/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/
-
B
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. https://www. bleepingcomputer.com/news/secu rity/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/
- Sep 19
-
P
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root https:// thehackernews.com/2026/09/publ ic-exploits-released-for-four-linux.html