Four Linux kernel local root flaws disclosed: DirtyAH6, PPPoEject, TUNderflow, DiagSpill
Four Linux kernel local privilege escalation vulnerabilities went public on 18 September 2026: DirtyAH6 (CVE-2026-80844), PPPoEject (CVE-2026-68121), TUNderflow (CVE-2026-81000) and DiagSpill (CVE-2026-74469). Working exploits are public; fixes landed in stable kernels 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4.
- All four bugs are local privilege escalations to root with public exploits
- Fixes shipped in kernels 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, 7.2.4
- Debian 12 bookworm still lacks a fix for TUNderflow (CVE-2026-81000)
- Proxmox VE patched only TUNderflow in proxmox-kernel-7.0 7.0.14-19
Read next
Software