- Sources: oss-security post, researcher write-up, HN discussion
- Summary: The embargo expired on four local privilege escalation bugs the researcher found through agentic vulnerability hunting: DirtyAH6 (CVE-2026-80844) in AH6, TUNderflow (CVE-2026-81000) in TUN, PPPoEject (CVE-2026-68121) in PPPoE and DiagSpill (CVE-2026-74469) in SCTP. DirtyAH6, TUNderflow and PPPoEject each require unprivileged user namespaces or capabilities, CAP_NET_ADMIN in every case and CAP_NET_RAW in addition for DirtyAH6, while DiagSpill requires neither and reaches root through SCTP and sctp_diag alone. The post also reports remote and container reachability: DirtyAH6 and DiagSpill are remotely reachable under specific conditions, DirtyAH6 was turned into remote root in a lab with on-target grooming, both can be turned into a remote crash or denial of service, and all four can corrupt the host kernel from a container, with DiagSpill needing no special capabilities where SCTP and sctp_diag are available, which the author notes could theoretically enable a container escape. For mitigation the post states that disabling unprivileged user namespaces removes the ordinary-user path to the first three but not to DiagSpill, that AH6, TUN, PPPoE and SCTP with sctp_diag can be disabled where unused, and that AppArmor and SELinux did not block the exploits in the author's testing except where Ubuntu blocks unprivileged user namespaces outright. The write-up marks the 2.6.12 to 5.9, 5.11 to 5.14, 5.16 to 6.0, 6.2 to 6.5, 6.7 to 6.11, 6.13 to 6.17 and 6.19 to 7.0 series end of life with no upstream stable fix, marks 7.1.y end of life for TUNderflow alone because 7.1.13 carries the DirtyAH6 fix, and names 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4 as the seven discrete stable releases that first carry all four fixes.
- Why it matters: Only DiagSpill gives an ordinary unprivileged user a root path with no namespace or capability requirement, and the released proof-of-concepts are built for a handful of targets rather than for every affected kernel, because each target needs custom derivation and grooming, while the bugs themselves reproduce across a range of distributions and kernels.
- Follow-up: Track whether any of the four reaches the CISA known exploited vulnerabilities catalog.
send feedback on this story