ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 7 sources: “Four 10-21-year-old Linux kernel local root flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) disclosed with PoC exploits; patch availability and distribution packaging limits…” — merged summary and timeline →

Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill

mediumVulnerabilityimportance 48
AI summary · glm-5.3-flash

oss-security follow-up on four Linux kernel local root vulnerabilities — DirtyAH6, PPPoEject, TUNderflow, DiagSpill — praising the advisory's disclosure quality.

A commenter on oss-security discusses the disclosure of four Linux kernel local privilege escalation vulnerabilities dubbed DirtyAH6, PPPoEject, TUNderflow, and DiagSpill. The post commends the advisory for listing fix commits, affected stable versions, exploitation prerequisites, vulnerable versions, and concrete mitigation targets. No CVE identifiers or confirmed in-the-wild exploitation are mentioned in the post.

  • Four Linux local root vulnerabilities disclosed: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
  • Advisory includes fix commits, affected stable versions, and exploitation prerequisites
  • Affected subsystems listed to enable targeted mitigations
  • Commenter notes more LPE disclosures appear to be coming
VendorsLinux
ProductsLinux kernel
Full article

Posted by Valtteri Vuorikoski on Sep 18 Credit where it's due: this is an excellent announcement (except for the bugs of course): * List of fix commits. * List of stable versions containing the fix. * Detailed pre-requisites for exploitation. * Concrete list of affected subsystems/modules to apply mitigations. * Clear list of vulnerable versions. * No Markdown, no extraneous LLM product placement, just the relevant bits in clear plaintext. With LPEs coming out...

This source does not provide full text. Read it at seclists.org.