Four Linux Kernel Root Exploits Go Public: DirtyAH6, TUNderflow, PPPoEject, and DiagSpill
Security researcher Asim Manizada published technical write-ups and working exploits for four Linux kernel local privilege escalation bugs on September 18, after holding them since mid-July so distributions could ship fixes first.
All four live in networking code that has been in the kernel for years, in some cases more than a decade. All four are fixed upstream and in every maintained stable branch.
The four bugs
| Name | CVE | Subsystem | What goes wrong |
|---|---|---|---|
| DirtyAH6 | CVE-2026-80844 | IPsec Authentication Header for IPv6 | ipv6_rearrange_rthdr() trusts segments_left without checking it against segments, so pointer arithmetic walks off the end of the header and memmove() writes out of bounds |
| TUNderflow | CVE-2026-81000 | TUN/TAP virtual network devices | tun_set_headroom() has no bounds check, and an oversized headroom makes a size calculation go negative and corrupt packet buffer boundaries. Present since kernel 4.6 |
| PPPoEject | CVE-2026-68121 | PPP over Ethernet | pppoe_sendmsg() keeps a pointer into a socket buffer across a call that can reallocate it, then writes through the stale pointer: a classic use-after-free |
| DiagSpill | CVE-2026-74469 | SCTP diagnostics (sctp_diag) | An association can hold 65,536 peer transports but the counter is 16 bits, so it wraps to zero and the diagnostic code reserves too little buffer space. Present since 4.7 |
Who is actually exposed
These are local escalations: an attacker needs to run code on the machine first. That makes them most serious on multi-user servers, shared build hosts, CI runners, and anything that runs untrusted code in containers.
The important qualifier is user namespaces. DirtyAH6, TUNderflow, and PPPoEject each need capabilities like CAP_NET_ADMIN, which an ordinary user can only get inside an unprivileged user namespace. On a distribution that allows those (most desktop distros do, because Flatpak, browsers, and rootless containers rely on them), an unprivileged account can reach all three.
DiagSpill is the odd one out. It needs no namespace or capability at all, only SCTP and sctp_diag support in the kernel. It can be triggered remotely only with non-default SCTP settings (ASCONF with authentication, or addip_noauth_enable=1), and remotely it is a crash rather than root.
Our explainers on Linux namespaces and rootless containers cover why the same feature that makes unprivileged containers possible keeps showing up as a kernel attack surface.
Fixed kernel versions
The first stable releases carrying all four fixes are:
| Branch | Fixed in |
|---|---|
| 7.2 | 7.2.4 |
| 6.18 | 6.18.50 |
| 6.12 | 6.12.109 |
| 6.6 | 6.6.157 |
| 6.1 | 6.1.188 |
| 5.15 | 5.15.221 |
| 5.10 | 5.10.270 |
Distribution kernels backport fixes without changing the upstream version number, so compare against your distro’s security tracker rather than uname -r alone. Our new guide on checking whether your kernel is patched against a CVE walks through doing that on Debian, Ubuntu, Fedora, and Arch.
Mitigations if you cannot reboot yet
Updating and rebooting is the fix. If that has to wait, you can shrink the attack surface:
# Block unprivileged user namespaces (stops three of the four)
# Debian/Ubuntu-style knob:
sudo sysctl -w kernel.unprivileged_userns_clone=0
# Generic knob, works everywhere but also breaks rootless containers:
sudo sysctl -w user.max_user_namespaces=0
# Stop the relevant modules loading if you do not use them
printf 'install %s /bin/false\n' sctp pppoe tun ah6 | sudo tee /etc/modprobe.d/lpe-quartet.conf
Both come with costs. Disabling user namespaces breaks Flatpak sandboxing, rootless Podman and Docker, and Chromium’s sandbox. Blocking tun breaks most VPNs, including WireGuard userspace implementations and OpenVPN. Only block what you have confirmed you do not use. Kernel modules explained covers how the install override works.
The AI angle
Manizada says the bugs were found with AI-assisted analysis of kernel memory handling. That fits the pattern of this whole kernel cycle, where language models have been finding error-path and bounds bugs at a rate that is visibly increasing fix volume. The same week, CISA added three other kernel CVEs to its exploited-in-the-wild catalog, so if you have been putting off a kernel update, this is the week to stop.