ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 10 sources: “Four aged Linux kernel local root flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) disclosed with public exploits; fixes in stable kernels 5.10.270–7.2.4” — merged summary and timeline →

Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill

mediumVulnerabilityimportance 45
AI summary · glm-5.3-flash

Follow-up on four Linux kernel local root flaws (DirtyAH6, PPPoEject, TUNderflow, DiagSpill), noting PPPoE is ubiquitous on ISP gateways.

An oss-security follow-up discusses four Linux local root vulnerabilities dubbed DirtyAH6, PPPoEject, TUNderflow, and DiagSpill. The commenter observes that PPPoE is widely deployed but mainly for ISP gateway communication rather than on end-user machines, which limits practical exposure. No CVE identifiers, patches, or exploitation evidence appear in the post.

  • Four Linux kernel flaws reportedly allow local root privilege escalation
  • PPPoE deployment is concentrated on ISP gateways, not end-user hosts
  • No CVE ids, patch details, or exploitation evidence cited in the follow-up
VendorsLinux
ProductsLinux kernel
Full article

Posted by SOFIA ETCHEPARE DARONCO on Sep 18 FWIW PPPoE is quite ubiquitous, though normally for gateway ISP communication rather than anything in end user machines.

This source does not provide full text. Read it at seclists.org.