hacker-news · Crawled Sep 19, 2026

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

4 CVEs
Read original article ↗

AI Summary

Security researcher Asim Manizada publicly released exploit code for four Linux kernel vulnerabilities—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—that enable local privilege escalation to root. All four flaws are memory-safety bugs in kernel networking code, with CVEs assigned and fixes available in updated kernel versions. While no in-the-wild exploitation has been reported, the public release of working, targeted exploits increases risk for unpatched systems, especially shared or multi-user environments. DiagSpill is particularly concerning as it requires no special privileges, only the SCTP module being loaded with non-default options.

AI-extracted · verify before operational use

Extracted Entities 4 found

MITRE ATT&CK TTPs 5 techniques