Four Linux kernel local privilege escalation flaws, each with a public proof-of-concept exploit, were disclosed by researcher Asim Manizada. All four sit in the kernel networking stack and each turns an unprivileged local account into root. Red Hat has published a combined bulletin (RHSB-2026-011), and distribution kernels are rolling out fixes.

The four bugs

NameCVEComponentBug classAffected since
DirtyAH6CVE-2026-80844IPv6 Authentication Header (AH6) processingOut-of-bounds access, insufficient routing-header validation2.6.12 (2005)
TUNderflowCVE-2026-81000TUN/TAPInteger underflow in packet-buffer calculation4.6
PPPoEjectCVE-2026-68121PPPoEUse-after-free after packet-buffer reallocation2.6.12
DiagSpillCVE-2026-74469SCTP diag reporting16-bit counter overflow, out-of-bounds write4.7

DirtyAH6. The segments_left field of an IPv6 Routing Header is not validated against the real number of segments. Crafted IPv6 packets cause roughly 4 KB of backwards pointer arithmetic, giving the attacker a kernel memory corruption primitive. The bug has existed for about two decades.

TUNderflow. An integer underflow in TUN/TAP packet-buffer length calculations leads to memory corruption.

PPPoEject. A packet buffer is reallocated while a stale pointer to the old one stays in use, a classic use-after-free.

DiagSpill. A 16-bit transport counter in the SCTP diag path overflows, causing a write of about 8 MiB past an allocated buffer. This is the most dangerous of the set from an access standpoint: it needs neither unprivileged user namespaces nor special capabilities, only that the SCTP module and sctp_diag reporting code are available on the host. Reports indicate that the crash-the-host variant depends on SCTP options that are off by default, but the root exploit has been published.

Exploitation prerequisites

DirtyAH6, TUNderflow and PPPoEject are reachable by an ordinary user only when unprivileged user namespaces are enabled, because the attacker needs CAP_NET_ADMIN inside a fresh network namespace to reach the vulnerable paths. That is the default on many distributions and is also what container runtimes and rootless tooling commonly rely on. DiagSpill needs no such gate.

Manizada reported the issues to the kernel security team in mid-July and found them with an AI-assisted research harness that reasons about kernel memory layout. This is the same trend seen in the recent DIBS loopback bug: automated tooling is shortening the path from code audit to working root exploit.

Impact

These are local flaws, not remote ones, but local root matters in infrastructure:

  • Multi-tenant hosts and shared CI runners. Any foothold, such as a compromised build job or a leaked low-privilege SSH account, becomes full host compromise.
  • Containers. A containerized process that can create user and network namespaces can attack the shared host kernel; kernel LPEs are a standard container-escape step.
  • Chained attacks. Initial access through a web-app RCE or stolen credentials is routinely followed by a public kernel exploit for privilege escalation. Public PoCs make that cheap.

The disclosure landed the same week CISA added three other Linux kernel flaws to its Known Exploited Vulnerabilities catalog, so defenders should assume weaponization of public kernel exploits is fast.

Mitigation

  1. Patch. Install the vendor kernel updates for your distribution (see Red Hat RHSB-2026-011 and your vendor’s tracker) and reboot, or use live patching where offered. Check each CVE against your kernel version; vendors backport, so version numbers alone are unreliable.
  2. Disable unprivileged user namespaces where workloads don’t need them. This closes the ordinary-user path to DirtyAH6, TUNderflow and PPPoEject:
    • Debian/Ubuntu-family: sysctl kernel.unprivileged_userns_clone=0 (or the AppArmor restriction on Ubuntu 23.10+)
    • RHEL-family: sysctl user.max_user_namespaces=0 Test first; rootless containers, some browsers’ sandboxes and Flatpak depend on them.
  3. Blacklist unused modules (sctp, sctp_diag, pppoe, tun, and IPv6 AH support) via /etc/modprobe.d/. For DiagSpill, removing SCTP is the direct fix when it isn’t needed.
  4. Harden container profiles. Keep default seccomp and AppArmor/SELinux profiles on, block unshare/clone with namespace flags for untrusted workloads, and prefer sandboxed runtimes for untrusted code.
  5. Hunt. Look for unexpected unshare -Urn activity, SCTP socket creation on hosts that don’t use SCTP, and unprivileged processes suddenly running with UID 0.

References