ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 7 sources: “Four 10-21-year-old Linux kernel local root flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) disclosed with PoC exploits; patch availability and distribution packaging limits…” — merged summary and timeline →

Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill

highVulnerabilityimportance 60
AI summary · glm-5.3-flash

oss-security follow-up on four Linux local root vulnerabilities—DirtyAH6, PPPoEject, TUNderflow, DiagSpill—debates distribution-specific patching challenges.

An oss-security thread discusses four Linux local privilege escalation vulnerabilities dubbed DirtyAH6, PPPoEject, TUNderflow and DiagSpill. This reply from Eli Schwartz addresses distribution patching logistics, noting that Gentoo's package manager does not support split subpackages, making fixes impossible to implement for gentoo-kernel-bin or binary package installs. The discussion underscores that some distributions face practical obstacles shipping patched kernels for these local root flaws.

  • Four Linux local root vulnerabilities nicknamed DirtyAH6, PPPoEject, TUNderflow and DiagSpill.
  • Reply focuses on packaging challenges rather than the flaws themselves.
  • Gentoo's package manager cannot implement split subpackages for gentoo-kernel-bin.
  • Binary package users face gaps in receiving fixed kernels.
Full article

Posted by Eli Schwartz on Sep 18 That is exactly what Hanno said to do, so I presume that he thinks it is as simple as that. There are, of course, challenges. Not all distribution package managers support split subpackages -- the Gentoo package manager does not, albeit people often compile from source on that distro ;) so it is redundant for the most part but also impossible to implement for "gentoo-kernel-bin", or for `--getbinpkg "gentoo-kernel"`. It also...

This source does not provide full text. Read it at seclists.org.