Four local root vulnerabilities (DirtyAH6, PPPoEject, TUNderflow, DiagSpill) in the Linux kernel, some with bugs dating back 10-21 years, have been publicly disclosed with fixes now in stable trees. All four allow unprivileged local users to escalate to root, with DiagSpill being the most concerning as it requires no special privileges, and DirtyAH6 potentially remote-groomable under specific conditions.
Background
Linux kernel vulnerabilities allowing local privilege escalation are among the most critical security issues, as they can turn a compromised low-privilege account into full root access. These findings affect multiple kernel versions from 5.10 through 7.2, indicating widespread impact across long-term supported and current releases.
- Source
- Lobsters
- Published
- Sep 18, 2026 at 03:57 PM
- Score
- 9.0 / 10