Researchers disclosed four Linux local privilege-escalation vulnerabilities dubbed DirtyAH6 (CVE-2026-80844), PPPoEject (CVE-2026-81000), TUNderflow (CVE-2026-68121), and DiagSpill (CVE-2026-74469). The flaws, identified through agentic vulnerability hunting, could allow a local attacker to obtain root-level privileges on affected Linux systems.
Oracle Linux issued ELSA-2026-500330 updates for Oracle Linux 7 and 8 systems running Unbreakable Enterprise Kernel packages, addressing all four CVEs. CVE-2026-68121 carries a CVSS v2 score of 10.0, while CVE-2026-74469 is rated high severity with low-privilege requirements; the vendor advisory reported no known exploits at publication. Organizations using affected UEK deployments should prioritize applying the available kernel updates and reboot systems into the patched kernel.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository published a destructive local Linux privilege-escalation proof of concept for DiagSpill (CVE-2026-74469), exploiting an SCTP diagnostic reply-size mismatch to overwrite kernel memory and corrupt page tables. The PoC targets specified Ubuntu 24.04 and Fedora 44 configurations and claims it can modify a worker process's credentials to obtain root access.
A GitHub repository published a destructive local privilege-escalation proof of concept for TUNderflow (CVE-2026-81000). The PoC uses TUN, Open vSwitch, netkit, and VXLAN objects to attempt an out-of-bounds OVS write, corrupt a pipe buffer, and overwrite /etc/pam.d/su; it was tested on specified Fedora 44 and Ubuntu 24.04.4 kernels.
A public proof of concept for CVE-2026-80844 was published, demonstrating a local Linux privilege-escalation path that corrupts socket-buffer metadata through malformed IPv6 AH6 processing and overwrites /etc/pam.d/su to seek root access. The PoC was tested on specified Fedora 43 and Ubuntu 24.04 kernels and warns it can corrupt memory or crash the host.
Oracle Linux released ELSA-2026-500330 for affected Oracle Linux 7 and 8 UEK kernel packages, addressing CVE-2026-68121, CVE-2026-74469, CVE-2026-80844, and CVE-2026-81000. The advisory stated that no known exploits were available.
CVE-2026-68121, CVE-2026-74469, CVE-2026-80844, and CVE-2026-81000 were published as vulnerabilities affecting Linux kernel-related components.
A GitHub repository published PPPoEject, a destructive local Linux privilege-escalation proof of concept for CVE-2026-68121. The exploit abuses a stale PPPoE header pointer after skb-head reallocation to redirect an fdtable entry to a fake file object and execute a controlled callback intended to obtain root privileges.
Research disclosed four Linux local privilege-escalation vulnerabilities, dubbed DirtyAH6, PPPoEject, TUNderflow, and DiagSpill, corresponding respectively to CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469. The research said the flaws were found through agentic vulnerability hunting and can yield root privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcegithub.com
Open sourceheyitsas.im
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.