Four newly disclosed Linux kernel vulnerabilities could allow local attackers to corrupt kernel memory and escalate privileges to root on affected systems. The flaws, named DirtyAH6, TUNderflow, PPPoEject, and DiagSpill, affect long-standing networking code and have now received upstream fixes. The vulnerabilities are tracked as CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469. DirtyAH6, tracked as CVE-2026-80844, affects IPv6 Authentication Header processing in Linux IPsec/XFRM code. The issue occurs when the kernel handles malformed IPv6 routing-header values without correctly validating the segments_left field. This can move an internal pointer outside the intended memory area and trigger an out-of-bounds memory...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!