Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
CVE Tools coverage
Working exploit code is public for four Linux kernel local privilege-escalation flaws: CVE-2026-80844 (DirtyAH6), CVE-2026-81000 (TUNderflow), CVE-2026-68121 (PPPoEject), and CVE-2026-74469 (DiagSpill). The bugs affect IPsec AH6, TUN/TAP, PPPoE, and SCTP code, allowing kernel-memory corruption that can give a local attacker root access; no in-the-wild exploitation has been reported. Update to a kernel release containing all fixes—starting with 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, or 7.2.4—or confirm that your distribution has backported them.