Vulnerability
Published 2026-09-18
Verified 2026-09-19

Linux local-root quartet: DirtyAH6 / PPPoEject / TUNderflow / DiagSpill (oss-security)

oss-security (18 September 2026) summarises four long-lived Linux kernel local privilege-escalation bugs nicknamed DirtyAH6 (CVE-2026-80844, xfrm/AH6 routing-header segments_left validation), PPPoEject (CVE-2026-68121, pppoe_sendmsg header pointer after dev_hard_header), TUNderflow (CVE-2026-81000, TUN/TAP oversized headroom underflow; CVSS 3.1 7.8), and DiagSpill (CVE-2026-74469, SCTP transport_count overflow; CVSS 3.1 8.8). First three LPEs generally need unprivileged user namespaces or specific capabilities; DiagSpill does not. Corruption in DirtyAH6 and DiagSpill can be remotely reachable only under very specific circumstances (oss-security). CVE records list stable-tree fixes and unaffected lines such as 5.10.269+/5.15.220+ (DirtyAH6), 5.10.270+/5.15.221+ (TUNderflow), 5.10.265+/5.15.216+ (PPPoEject/DiagSpill) among others — apply your distro’s kernel security updates rather than cherry-picking. No CVSS published yet in the CVE JSON for DirtyAH6 (CVE-2026-80844) at fetch time — do not invent. Primary: oss-security roundup; also MITRE CVE records / kernel stable commits.

Product
Linux kernel (xfrm/AH6, PPPoE, TUN/TAP, SCTP)
Versions
Long-standing; fixed in multiple stable trees (examples from CVE: DirtyAH6 unaffected 5.10.269 / 5.15.220+; TUNderflow 5.10.270 / 5.15.221+; PPPoEject & DiagSpill 5.10.265 / 5.15.216+ — confirm against your distro advisory)
CVSS
(CVSS 3.1 High; DiagSpill CVE-2026-74469; TUNderflow/PPPoEject 7.8; DirtyAH6 unpublished at fetch)
Exploited in Australia?
unknown
Patch to
Install distribution kernel security updates that include the stable commits for CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469; reboot into the new kernel.

Primary: oss-security — DirtyAH6 / PPPoEject / TUNderflow / DiagSpill (18 Sep 2026) · Vendor: CVE-2026-81000 (TUNderflow) — also 80844 / 68121 / 74469 on cve.org · CVE: CVE-2026-80844, CVE-2026-68121, CVE-2026-81000, CVE-2026-74469 · CVE-2026-74469 (DiagSpill) CVSS 8.8; see also CVE-2026-80844 / 68121

vulnerabilities network