Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: sctp (1 article)Clear

Public exploits released for four Linux kernel flaws that grant local root

Researcher Asim Manizada published working exploit code on September 18 for four Linux kernel local privilege escalation flaws, each letting a local user gain root. The bugs are DirtyAH6 in IPsec AH6, TUNderflow in TUN/TAP, PPPoEject in PPPoE, and DiagSpill in SCTP diagnostics. Kernel maintainers fixed all four in recent weeks after a coordinated hold with distributions, and no in-the-wild abuse has been reported. Three require unprivileged user namespaces, which many distributions enable by default, while DiagSpill needs only an available SCTP module. The exploits are tuned to specific builds and can crash machines, but public code raises risk on shared multi-user systems.

Check
Update to the patched kernel across multi-user and shared hosts, then verify the running kernel version rather than the installed package alone.
Affected
Any low-privileged local account on an unpatched kernel can escalate to root, especially where unprivileged user namespaces or the SCTP module are available.
Fix
Apply kernel updates, disable unprivileged user namespaces and blacklist the SCTP module where not needed, and prioritize shared servers with local users.