Packaging replies follow four Linux local root flaws
oss-security replies weigh packaging limits for four named Linux kernel local roots, with no CVEs or exploitation claims.
Two oss-security follow-ups discuss a previously disclosed quartet of Linux kernel local root vulnerabilities nicknamed DirtyAH6, PPPoEject, TUNderflow, and DiagSpill. On 2026-09-20, Roman Fiedler suggested splitting the kernel into per-module packages to reduce transferred data and potentially limit exposure, while doubting the benefit given modern network and disk sizes and noting that module selection across diverse hardware could make installation cumbersome. On 2026-09-22, Eli Schwartz said the proposal needs package managers that generate dependency metadata at packaging time, support Provides, and handle an equals token in version fields. The excerpts give no CVE identifiers, patches, exploit details, or reports of exploitation. The reports do not contradict each other; they describe different replies in the same thread.
- Thread concerns four Linux kernel local root vulnerabilities nicknamed DirtyAH6, PPPoEject, TUNderflow, and DiagSpill.
- On 2026-09-20, Roman Fiedler suggested per-module kernel packages could shrink the installed footprint, reduce transferred data, and potentially limit exposure.
- Fiedler doubted that benefit given gigabit networking and large disks, and said selecting modules across diverse hardware could complicate installation.
- On 2026-09-22, Eli Schwartz said the idea needs package managers that generate dependency metadata at packaging time, support Provides, and handle an equals token in version fields.
- Neither excerpt includes CVE identifiers, patches, exploit details, or claims of in-the-wild use.
Coverage timelineoldest first · each row is one article
- · 6d agoRe: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
oss-security· 40
Follow-up discussion on four Linux kernel local root vulnerabilities (DirtyAH6, PPPoEject, TUNderflow, DiagSpill) weighs per-module kernel packaging trade-offs.
- · 5d agoRe: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
oss-security· 35
An oss-security reply discusses packaging limits around four named Linux local root vulnerabilities.