Public exploits now turn four Linux networking memory corruptions into local root shells.
Four target-specific chains start from an ordinary local account.
Linux kernel networking subsystems AH6/XFRM, TUN/TAP with Open vSwitch, PPPoE, and SCTP diagnostics across supported and historical kernel series.
Local root through four feature-dependent kernel-memory corruption chains
This is not identifier churn: public grooming and end-to-end chains now convert four feature-dependent corruptions into root from an ordinary account.
Detail, proof-of-concept code and 5 sources
DirtyAH6, TUNderflow and PPPoEject use unprivileged user and network namespaces; DiagSpill instead needs SCTP and sctp_diag.
The chains redirect the corruptions through file-backed pages, an fdtable or callback, or page tables, then install credentials, a PAM rule or a sudoers entry and open a root shell. The report maps each flaw to fixed stable releases.
- access:local:unprivileged
- code running as an unprivileged local user
- Revocation complete
- Yes
- Reaches end-of-life hardware
- No
The revocation answer means no revocation is required by this source-code fix. The EOL answer is scoped to upstream stable releases; downstream vendor backports were not established.