hacker-news · Crawled Sep 19, 2026
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
4 CVEs
Read original article ↗
AI Summary
Security researcher Asim Manizada publicly released exploit code for four Linux kernel vulnerabilities—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—that enable local privilege escalation to root. All four flaws are memory-safety bugs in kernel networking code, with CVEs assigned and fixes available in updated kernel versions. While no in-the-wild exploitation has been reported, the public release of working, targeted exploits increases risk for unpatched systems, especially shared or multi-user environments. DiagSpill is particularly concerning as it requires no special privileges, only the SCTP module being loaded with non-default options.
AI-extracted · verify before operational use