Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Public Exploits for Linux Kernel Flaws Released

Public Exploits for Linux Kernel Flaws Released

Posted on September 18, 2026 By CWS

A recent disclosure by a security researcher has unveiled exploit codes for four vulnerabilities in the Linux kernel, enabling local users to potentially acquire root access. These vulnerabilities, which pose significant risks, highlight the need for system updates to mitigate potential threats. The researcher, Asim Manizada, revealed these flaws after they were patched by kernel maintainers, emphasizing the urgency for users to update their systems.

Details of the Linux Kernel Flaws

The four vulnerabilities, named DirtyAH6, TUNderflow, PPPoEject, and DiagSpill, were found by Manizada and reported to the Linux security team in July. Manizada publicly disclosed the exploit codes on September 18, after ensuring that patches were available for affected systems. While these exploits have not yet been used in real-world attacks, their public availability increases the risk, particularly for machines with outdated kernels.

Among these, three require unprivileged user namespaces to be enabled, which is a feature allowing users to perform root-level actions within a sandbox environment. DiagSpill, however, does not require such namespaces, posing a broader risk. The vulnerabilities allow attackers to corrupt kernel memory, potentially leading to system crashes or unauthorized root access.

Potential Impact and Risk Mitigation

Manizada also noted that DirtyAH6 and DiagSpill could theoretically be triggered remotely, though practical exploitation is highly challenging. DirtyAH6 can crash systems configured as IPv6 routers if they implement an IPsec Authentication Header, while DiagSpill can crash systems with certain SCTP settings enabled. The exploits were tested in controlled environments, indicating limited remote application.

To protect systems, users are advised to upgrade to the latest kernel versions that include fixes for these vulnerabilities. The first stable releases addressing all flaws include versions 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, and 7.2.4. Users should verify with their distribution’s security advisories to ensure these patches are applied.

Understanding the Nature of the Bugs

These vulnerabilities stem from memory-safety issues within the kernel’s networking code. DirtyAH6, for instance, involves mishandled routing headers, allowing out-of-bounds memory writes. TUNderflow relates to incorrect size calculations in virtual network devices, while PPPoEject involves use-after-free errors in PPP over Ethernet code. DiagSpill results from insufficient endpoint tracking, leading to buffer overflows.

Manizada’s discovery process was aided by AI tools that map kernel memory handling, illustrating a growing trend in using technology to uncover security flaws. His work not only addresses current threats but also emphasizes the potential for further discoveries using similar methods.

In conclusion, the release of these exploit codes underscores the importance of regular system updates and proactive security measures. While the immediate threat may be limited, the potential for misuse remains, urging organizations and individuals to stay vigilant and responsive to security advisories.

The Hacker News Tags:AI-assisted discovery, Cybersecurity, exploit code, Kernel, Linux, Manizada, memory safety bugs, Networking, public exploits, root access, Security, system update, tech news, user namespaces, Vulnerabilities

Post navigation

Previous Post: Linux Kernel Vulnerabilities Pose Root Access Risks
Next Post: Hackers Exploit ChatGPT Alerts for Credential Theft

Related Posts

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation The Hacker News
Critical Vulnerabilities in FatFs Impact Millions of Devices Critical Vulnerabilities in FatFs Impact Millions of Devices The Hacker News
Critical Acronis cPanel Plugin Flaw Exploited Critical Acronis cPanel Plugin Flaw Exploited The Hacker News
UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats The Hacker News
OpenAI Introduces ChatGPT Lockdown Mode for Enhanced Security OpenAI Introduces ChatGPT Lockdown Mode for Enhanced Security The Hacker News
Linux AppArmor Vulnerabilities Risk Root Escalation Linux AppArmor Vulnerabilities Risk Root Escalation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit ChatGPT Alerts for Credential Theft
  • Public Exploits for Linux Kernel Flaws Released
  • Linux Kernel Vulnerabilities Pose Root Access Risks
  • AI Agents Lead New Wave of Ransomware Threats
  • Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit ChatGPT Alerts for Credential Theft
  • Public Exploits for Linux Kernel Flaws Released
  • Linux Kernel Vulnerabilities Pose Root Access Risks
  • AI Agents Lead New Wave of Ransomware Threats
  • Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark