Linux-Kernel
DirtyAH6, TUNderflow, PPPoEject, DiagSpill: Four Public Linux Kernel Root Exploits Land in the Networking Stack
Researcher Asim Manizada published working local-root exploits for four Linux kernel networking-stack flaws, three reachable via unprivileged user namespaces, one via SCTP diag with no special privileges.
CVE-2026-72018: AI Agent Turns a 16-Byte Linux Kernel Zero-Write Into Local Root
XBOW's autonomous agent found and weaponized a missing bounds check in the Linux kernel's DIBS loopback driver (SMC-D), escalating a constrained out-of-bounds write to root via cred structure corruption.
CVE-2026-89775: KVM/arm64 Nested-Virtualization Bug Gives Guests Read-Write Access to Host Kernel Memory
A type-truncation bug in KVM/arm64's stage-1 page-table walk lets a guest keep a writable mapping to a freed host kernel page, enabling guest-to-host escape on ARM64 hosts with nested virtualization enabled.
Branch Target Reuse: New Spectre v2 Variant Leaks Linux Root Password Hash Through the cBPF JIT
VUSec's Branch Target Reuse abuses stale indirect-branch predictions over freed JIT memory to leak a root password hash from Linux in 3-5 minutes; kernel fixes for CVE-2026-64507 and CVE-2026-64508 are merged.
CVE-2026-80521: Unpatched Ubuntu AF_UNIX Race Lets Containers Escape to Host Root
A public exploit for CVE-2026-80521, a use-after-free race in the Linux kernel's AF_UNIX socket garbage collector, lets an unprivileged process inside a default Docker or Kubernetes container break out to root on the host โ and Ubuntu still hasn't shipped the fix.
CISA Adds Three Linux Kernel Flaws to KEV: TLS Receive Path, ebtables SNAT, and AF_ALG Race Condition Under Active Exploitation
CISA added three Linux kernel CVEs to its Known Exploited Vulnerabilities catalog on evidence of in-the-wild exploitation โ a CVSS 9.8 TLS receive-path flaw, an 8.8 ebtables SNAT out-of-bounds write, and a 7.8 AF_ALG race condition โ with FCEB remediation due September 21.
SCTPhantom (CVE-2026-64564): An 18-Year-Old Linux Kernel SCTP Bug Gives Local Root and Escapes Containers
A use-after-free in the Linux kernel's SCTP ASCONF transport handling, present since 2008, lets a local attacker with SCTP reachability escalate to root and, on affected configurations, escape containers.
OVSwrap (CVE-2026-64531): 13-Year-Old Linux Kernel Bug in Open vSwitch Gives Any Local User Root
A 16-bit integer wraparound in the Linux kernel's Open vSwitch action parser (CVE-2026-64531, 'OVSwrap') lets any unprivileged local user become root โ no OVS configuration, no CAP_NET_ADMIN, no container privileges required. A public PoC ships precomputed offsets for ~800 kernel builds.
RefluXFS (CVE-2026-64600): A Nine-Year-Old XFS Race Condition Roots 16.4 Million Linux Systems
A race condition in the XFS copy-on-write path lets any local user overwrite protected files and gain root โ no SELinux bypass needed, no workaround available. Patch and reboot is the only fix.
GhostLock (CVE-2026-43499): A 15-Year-Old Futex Bug Gives Any Local User Root โ and Breaks Out of Containers
A use-after-free in the Linux kernel's futex requeue-PI code, present since 2011, lets any unprivileged local user gain root with a public, 97%-reliable exploit that also escapes Docker and Kubernetes containers.
Januscape (CVE-2026-53359): A 16-Year-Old KVM Bug Lets Guests Escape to the Host
A use-after-free in KVM's shadow MMU, present since 2010, lets a guest VM with nested virtualization corrupt host kernel memory and potentially execute code on the hypervisor โ patched July 4 across Intel and AMD x86.
Bad Epoll (CVE-2026-46242): A Six-Instruction Race in epoll() Roots Linux 6.4+ and Android
A use-after-free race in the Linux epoll subsystem, introduced by a 2023 commit, lets an unprivileged local user gain root with a 99%-reliable exploit โ and the same code path may be reachable from Chrome's renderer sandbox on Android.
DirtyClone: Linux Kernel LPE via Cloned sk_buff Gives Any Local User Root (CVE-2026-43503)
JFrog releases a working exploit for DirtyClone, a Linux kernel socket-buffer cloning flaw that silently rewrites in-memory setuid binaries and grants rootโwith container escape potential on cloud and Kubernetes hosts.
Linux Kernel CVE-2026-46331: Pedit COW Traffic-Control Bug Delivers Root Shell, Ubuntu Still Unpatched
A weaponized PoC for CVE-2026-46331 (Pedit COW) corrupts the kernel page cache via act_pedit to drop a root shell; Ubuntu 18.04โ26.04 remain unpatched.
DirtyDecrypt (CVE-2026-31635): Public PoC Roots Fedora, Arch, and openSUSE via the Kernel's RxGK Path
A released proof-of-concept weaponizes CVE-2026-31635, a missing copy-on-write guard in the Linux kernel's RxGK receive path, for local root on Fedora, Arch, and openSUSE Tumbleweed โ and pod escape on affected worker nodes.
ssh-keysign-pwn (CVE-2026-46333): Six-Year-Old Linux Kernel Race Hands Unprivileged Users SSH Host Keys and /etc/shadow
Qualys disclosed a six-year-old logic flaw in __ptrace_may_access that lets any local user race ssh-keysign and chage out of their host keys and shadow file. Public PoC works out of the box on Debian, Ubuntu, Arch, and the EL9/EL10 families. Patch or set kernel.yama.ptrace_scope=2 now.
Dirty Frag: Chained Linux Kernel Bugs Hand Out Root, One Half Still Unpatched
Dirty Frag chains an xfrm-ESP page-cache write (CVE-2026-43284) with an unpatched RxRPC page-cache write (CVE-2026-43500) for reliable root on most Linux distros. Embargo blew up early โ public PoC is out, RxRPC fix is not.
Copy Fail (CVE-2026-31431): A 732-Byte Python Script Roots Every Major Linux Distro Since 2017
A nine-year-old logic bug in the kernel's algif_aead crypto interface lets an unprivileged user plant four bytes anywhere in the page cache โ including inside a setuid binary's cached pages. Root in seconds, no on-disk artifacts, breaks containers.
CVE-2026-31414: Linux Kernel Netfilter Conntrack Flaw Enables Container Escape Privilege Escalation
A use-after-free in Linux kernel netfilter connection tracking allows local privilege escalation from container workloads โ patch your nodes now.
CVE-2026-23442: Remote Kernel Panic via SRv6 NULL Pointer Dereference Threatens IPv6 Infrastructure
A CVSS 8.2 flaw in the Linux kernel's SRv6 implementation lets remote attackers crash systems with crafted IPv6 packets. Patches are outโupdate now.