Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: user-namespaces (2 articles)Clear

Public exploits released for four Linux kernel flaws that grant local root

Researcher Asim Manizada published working exploit code on September 18 for four Linux kernel local privilege escalation flaws, each letting a local user gain root. The bugs are DirtyAH6 in IPsec AH6, TUNderflow in TUN/TAP, PPPoEject in PPPoE, and DiagSpill in SCTP diagnostics. Kernel maintainers fixed all four in recent weeks after a coordinated hold with distributions, and no in-the-wild abuse has been reported. Three require unprivileged user namespaces, which many distributions enable by default, while DiagSpill needs only an available SCTP module. The exploits are tuned to specific builds and can crash machines, but public code raises risk on shared multi-user systems.

Check
Update to the patched kernel across multi-user and shared hosts, then verify the running kernel version rather than the installed package alone.
Affected
Any low-privileged local account on an unpatched kernel can escalate to root, especially where unprivileged user namespaces or the SCTP module are available.
Fix
Apply kernel updates, disable unprivileged user namespaces and blacklist the SCTP module where not needed, and prioritize shared servers with local users.

OVSwrap kernel flaw gives local users root on most Linux distributions

A researcher disclosed OVSwrap, a Linux kernel flaw in the Open vSwitch datapath that lets an ordinary local user gain root, and published a working exploit covering roughly 800 builds. Tracked as CVE-2026-64531, it is an integer wraparound in how Open vSwitch handles internally generated network action streams, giving a deterministic memory-corruption path. The attacker needs no existing switch, no running daemon, and no special privileges: where unprivileged user namespaces are enabled, they create a private namespace, gain network capabilities inside it, and reach the vulnerable code. The module can even auto-load on demand, so an empty module list does not mean safety. Default configurations of most major distributions tested as exploitable.

Check
Install the patched vendor kernel, which upstream fixed on July 24, and where you cannot patch immediately, disable unprivileged user namespaces to cut off the main path to the flaw.
Affected
Most default-configured Linux systems with the Open vSwitch module available and unprivileged user namespaces enabled (CVE-2026-64531); an ordinary local user can corrupt kernel memory and gain root, with a public exploit available.
Fix
Apply patched kernels and reboot, restrict unprivileged user namespaces where feasible, and prioritize shared and multi-tenant hosts, since any local foothold from another flaw or stolen access can escalate to full control.