Public Root Exploits Drop for Four Decade-Old Bugs Buried in the Linux Kernel Network Stack
Researcher Asim Manizada published proof-of-concept root exploits on 18 September 2026 for four Linux kernel local privilege escalations (CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, CVE-2026-74469). DiagSpill needs no user namespaces. No wild use is reported.

The Hacker News (Swati Khandelwal, 18 September 2026) reported that researcher Asim Manizada published working exploit code for four Linux kernel flaws that each let a local user gain root. He reported the bugs to the Linux kernel security team in mid-July and held publication so distributions could ship fixes. GBHackers carried the same disclosure.
This is a coordinated researcher disclosure plus public proof-of-concept exploits dated 18 September 2026. It is not a report of wild exploitation, and it is not a remote unauthenticated code-execution campaign.
The four names are DirtyAH6 (CVE-2026-80844) in IPsec AH6, TUNderflow (CVE-2026-81000) in TUN/TAP, PPPoEject (CVE-2026-68121) in PPPoE, and DiagSpill (CVE-2026-74469) in SCTP sock_diag. All four are memory-safety bugs in networking code. The underlying mistakes are about 10 to 21 years old.
DirtyAH6 is an out-of-bounds write from an unvalidated IPv6 routing-header field. TUNderflow is an integer wrap on oversized receive headroom via an Open vSwitch path. PPPoEject is a use-after-free in pppoe_sendmsg after a buffer realloc. DiagSpill wraps a 16-bit peer-transport counter at 65,536 and overwrites about 8 MiB.
Three ordinary-user paths need unprivileged user namespaces. DiagSpill does not, as long as SCTP and sctp_diag are available.
DirtyAH6 has a narrow remote crash on IPv6 routers that add an Authentication Header in transport mode. Manizada reached remote root only in his lab, and only with memory shaping he called "extremely difficult." DiagSpill has a crash-only remote path with non-default SCTP options. The proof-of-concept exploits are tuned to specific kernel builds and can crash machines, so they are meant for isolated test systems.
The first complete upstream stable set is 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, and 7.2.4. Distributions use their own package versions. Confirm the vendor advisory lists all four CVEs.
If a host is still unpatched, disabling unprivileged user namespaces closes the ordinary-user path to DirtyAH6, TUNderflow, and PPPoEject, but not DiagSpill. Unused AH6, TUN/TAP, PPPoE, and SCTP can be turned off as a temporary cut. Patching is preferred. AppArmor and SELinux did not block the reported exploit paths in Manizada's testing, GBHackers reported.
The DirtyAH6 fix commit includes an Assisted-by credit for Manizada's custom tooling. This batch follows his July OVSwrap disclosure. One exploit reuses a Dirty Frag technique from May.
Related privilege-escalation tape includes CrowdStrike FalconFlank, the Cisco Nexus 9000 Silicon One root RCE, and Check Point management-server root.
If you run multi-user Linux hosts or containers with SCTP or unprivileged user namespaces still on, apply the vendor kernel that lists all four CVEs today, then disable unused AH6, TUN/TAP, PPPoE, and SCTP until that package is live.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free