Four vulnerabilities discovered in different Linux kernel networking subsystems allow a local unprivileged account to escalate its privileges to root on affected systems. The flaws, dubbed DirtyAH6, TUNderflow, PPPoEject and DiagSpill and tracked as CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469, were publicly disclosed on September 18, 2026, after the coordinated embargo expired.

The key facts about the four Linux vulnerabilities in 20 seconds

  • Four flaws affect the Linux kernel’s XFRM/AH6, TUN, PPPoE and SCTP subsystems.
  • All four can allow a local user to escalate privileges to root on affected targets.
  • The first three require unprivileged user/network namespaces or specific capabilities.
  • DiagSpill does not require unprivileged user namespaces and can also cause remote denial of service in certain configurations.
  • Fixes have already reached several stable kernel branches, from Linux 5.10 through the latest releases.

Security researcher Asim Manizada reported the four issues to the Linux kernel security team and the relevant maintainers in mid-July. According to his analysis, the underlying bugs had been present in the code for between 10 and 21 years. The public disclosure followed the expiration of a coordinated embargo with the linux-distros mailing list.

The most relevant point for administrators is not simply the age of the bugs, but that all four have publicly available proof-of-concept code demonstrating local privilege escalation to root on affected targets. Red Hat has classified the vulnerabilities as important-impact issues and is distributing fixes for affected systems.

Four bugs, four different parts of the Linux kernel

The vulnerabilities do not come from a single component. Each one affects a different part of Linux’s networking stack and has its own set of requirements.

VulnerabilityCVESubsystemKey requirement
DirtyAH6CVE-2026-80844IPv6 AH/XFRMAH6/XFRM and a user/network namespace or specific capabilities
TUNderflowCVE-2026-81000TUN/TAPTUN and a network path capable of propagating excessive headroom
PPPoEjectCVE-2026-68121PPPoEPPPoE and a header callback capable of reallocating the skb
DiagSpillCVE-2026-74469SCTP/sctp_diagSCTP and sctp_diag, with no user-namespace requirement

The table reflects the requirements described by the researcher and confirmed in security advisories. It does not mean that every Linux installation is automatically exploitable: the proof-of-concept exploits have additional dependencies and target specific systems and configurations.

DirtyAH6: an IPv6 and AH6 issue

DirtyAH6 affects IPv6 routing-header processing within AH6, the authentication mechanism used by IPsec. The problem occurs when the kernel calculates the number of addresses from hdrlen but does not properly check that segments_left is within that limit.

According to the published analysis, an IPv6 packet crafted with specific values could cause the kernel to move a pointer thousands of bytes backwards and execute a memmove() outside the expected bounds. The vulnerability is tracked as CVE-2026-80844.

The researcher also demonstrated remote impact under very specific conditions when the system acts as an IPv6 router or gateway and uses AH in transport mode. In a laboratory environment, he was able to achieve remote root execution using additional memory-grooming techniques, although he considers remote-only exploitation extremely difficult.

TUNderflow: when excessive headroom exceeds kernel limits

TUNderflow, CVE-2026-81000, affects the TUN device and the way Linux handles the space reserved before packet data. The issue involved the use of tun->align both to calculate headroom and to determine how much data should remain in the linear portion of the skb.

The exploitation chain described by the researcher can involve Netkit, VXLAN and Open vSwitch (OVS), which can propagate an excessively large headroom request to TUN. Under certain conditions, the calculation could underflow and ultimately place skb->data outside the allocated memory area.

Debian documents the upstream fix, which limits the headroom stored by TUN to the available skb header budget and also corrects handling of non-linear packets.

PPPoEject: a pointer that no longer points to valid memory

PPPoEject, CVE-2026-68121, affects PPPoE processing. The kernel retained a pointer to the packet header before calling dev_hard_header(), even though that operation can trigger reallocation of the skb head.

If the memory is moved, the old pointer is no longer valid. Subsequent code could nevertheless continue using it to write information into an area that no longer corresponded to the original skb.

Red Hat documents a particularly specific situation in which the reallocation could occur while a copy operation was blocked and a port was being added to certain network devices. The fix reloads the header pointer using the offset stored in the skb.

DiagSpill: a 16-bit counter that wraps around

DiagSpill, CVE-2026-74469, is different from the other three vulnerabilities. It affects the SCTP subsystem and its sctp_diag diagnostic interface.

An SCTP association can have up to 65,536 peer transports, but the counter used by the kernel was only 16 bits wide. When the limit was reached, the counter could wrap back to zero. sctp_diag would then calculate the required buffer space using the incorrect value while continuing to iterate over and copy the complete transport list.

The result could be a write of approximately 8 MiB beyond the intended buffer, according to Red Hat’s documentation.

DiagSpill also differs from the other vulnerabilities because it does not require an unprivileged user namespace or special capabilities for local exploitation, provided SCTP and sctp_diag are available. Under certain configurations involving ASCONF/ADD-IP, SCTP-AUTH or the net.sctp.addip_noauth_enable=1 option, it can also be triggered remotely to cause a crash or denial of service.

The fixes are already available

The researcher identifies 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4 as the first stable releases containing all four fixes. Linux distributions, however, publish their own patched kernel packages and update schedules, so administrators should not rely solely on the upstream version number.

The Debian case illustrates why administrators should check the kernel version supplied by their specific distribution. For several of these vulnerabilities, Debian Bookworm fixes the issues in specific kernel packages, while Trixie, Forky and Sid have different package versions and patch statuses.

Administrators should first identify the kernel running on each system and then consult the security advisory published by their distribution. On Linux servers used for virtualization, network infrastructure or multi-user environments, this review is particularly relevant because the local threat model can include users, containers or processes with specific capabilities.

As a temporary mitigation, the researcher recommends disabling unprivileged user namespaces where the configuration permits it, although that measure does not cover DiagSpill and does not protect against processes or containers that already have the required capabilities. Another option is to disable AH6, TUN, PPPoE or SCTP/sctp_diag when they are not required.

Red Hat similarly recommends upgrading to patched kernels and specifically notes that restricting unprivileged user namespaces reduces the attack surface for the first three vulnerabilities, but does not eliminate the risk associated with DiagSpill.

The disclosure also includes proof-of-concept code for all four vulnerabilities in separate repositories. This can help security teams validate their systems, but the availability of public PoCs also makes it more important to perform testing in controlled environments and deploy the corresponding updates to production systems.

The case has another noteworthy characteristic: the four bugs affect networking components with very different functions and histories, and some had remained in the kernel for more than a decade. The age of a code path alone therefore does not indicate whether it is outside the scope of new security research. For administrators, the practical response remains to understand which modules are active, disable unnecessary components and keep kernels and security packages updated.

Frequently asked questions

What are DirtyAH6, TUNderflow, PPPoEject and DiagSpill?

They are four Linux kernel vulnerabilities tracked as CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. They affect AH6/XFRM, TUN, PPPoE and SCTP/sctp_diag, respectively.

Can they provide root access on Linux?

Yes. The proof-of-concept exploits published by the researcher demonstrate escalation from an unprivileged local user to root on affected targets. The exact exploitation conditions depend on the vulnerability and the system configuration.

Which Linux versions are patched?

The first stable branches containing all four fixes are 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4. Linux distributions may apply the fixes through different package versions, so their own security advisories should be checked.

Do all the affected components need to be enabled?

No. Each vulnerability has different requirements. Disabling AH6, TUN, PPPoE or SCTP/sctp_diag when they are not needed can reduce the attack surface, but updating the kernel remains the primary mitigation.

Scroll to Top