Skip to finding
§
High
Linux kernel
Confirmed
CVE-2026-80844

Public exploits now turn four Linux networking memory corruptions into local root shells.

Four target-specific chains start from an ordinary local account.

Affects

Linux kernel networking subsystems AH6/XFRM, TUN/TAP with Open vSwitch, PPPoE, and SCTP diagnostics across supported and historical kernel series.

What it enables

Local root through four feature-dependent kernel-memory corruption chains

Attacker starts as an ordinary local user on a build exposing the required subsystem and configuration.→↓For DirtyAH6, TUNderflow, or PPPoEject, the attacker creates a user/network namespace and assembles the required virtual networking path; DiagSpill instead requires SCTP diagnostics.→↓The selected bug corrupts kernel-managed memory.→↓The published target-specific grooming redirects the corruption into a file-backed page, fdtable/callback, or page tables.→↓The exploit replaces a PAM rule, installs credentials or a sudoers entry, and opens a root shell.
Why this matters

This is not identifier churn: public grooming and end-to-end chains now convert four feature-dependent corruptions into root from an ordinary account.

Detail, proof-of-concept code and 5 sources
Required access

An ordinary local account on a compatible build; three exploits use unprivileged user/network namespaces, while DiagSpill needs SCTP and sctp_diag but no namespace capability

Affected versions

DirtyAH6: affected series through 5.10.268, 5.15.219, 6.1.186, 6.6.155, 6.12.107, 6.18.48, 7.1.12 and 7.2.2, plus affected EOL series, TUNderflow: affected series through 5.10.269, 5.15.220, 6.1.187, 6.6.156, 6.12.108, 6.18.49 and 7.2.3, plus affected EOL series, PPPoEject: affected series through 5.10.264, 5.15.215, 6.1.182, 6.6.147, 6.12.100, 6.18.41 and 7.1.5, plus affected EOL series, DiagSpill: affected series through 5.10.264, 5.15.215, 6.1.182, 6.6.150, 6.12.102, 6.18.43 and 7.1.7, plus affected EOL series

Proof of concept

Public exploit code →

DirtyAH6, TUNderflow and PPPoEject use unprivileged user and network namespaces; DiagSpill instead needs SCTP and sctp_diag.

The chains redirect the corruptions through file-backed pages, an fdtable or callback, or page tables, then install credentials, a PAM rule or a sudoers entry and open a root shell. The report maps each flaw to fixed stable releases.

Evidence
Researcher's technical report states successful root reproduction and documents each chainFour public repositories contain target-specific root reproductionsUpstream stable fixed-release mapping is included in the original report
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026