discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

Security researcher Asim Manizada released working exploit code for four Linux kernel flaws that let a local user gain root access. Kernel maintainers have fixed all four over the past few weeks.

By Swati Khandelwal·Sep 18·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Image: thehackernews.com

A security researcher has released exploit code for four Linux kernel flaws that enable local root access. Kernel fixes are available, but older systems remain vulnerable.

Why it matters

The flaws affect three of the four vulnerabilities, which can be exploited by unprivileged users with user namespaces enabled. Users should update to the latest kernel versions to protect their systems.

A security researcher found four bugs in the Linux kernel that let someone who isn't root take control of a computer. The bugs are fixed in the latest version of the Linux kernel, but older versions are still vulnerable.

Analysis

{"

User Namespaces and Flaws 1 & 2 (DirtyAH6 & TUNderflow)":"User namespaces are a Linux feature that allow a normal user to act as root inside a private sandbox. Asim Manizada found that DirtyAH6 and TUNderflow can be exploited by unprivileged users with user namespaces enabled. These flaws are fixed in the latest kernel versions.","

Flaw 3 (PPPoEject)":"PPPoE is a protocol used for connecting to the internet via a dial-up connection. Asim Manizada found that the PPPoE code can be exploited by unprivileged users with user namespaces enabled. This flaw is also fixed in the latest kernel versions.","

Flaw 4 (DiagSpill)":"DiagSpill is a flaw in the SCTP (sctp_diag) code. Asim Manizada found that this flaw can be triggered by turning on certain SCTP options. This flaw is also fixed in the latest kernel versions."}

Key points

  • Four Linux kernel flaws were found and released as exploit code
  • Kernel fixes are available, but older systems remain vulnerable
  • User namespaces and specific network protocols are necessary to exploit the flaws
  • The latest kernel versions include fixes for all four flaws
  • Users should update to the latest kernel versions to protect their systems
The Upside

The fixes for these bugs are available in the latest kernel versions, so users can protect their systems by updating to the latest version.

The Downside

If users do not update to the latest kernel versions, they may still be vulnerable to these bugs, which could allow an attacker to take control of their computers.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritylinuxkernelprivilege-escalationuser-namespaces

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 18, 2026

Source

thehackernews.com

Share

Topics

securitylinuxkernelprivilege-escalationuser-namespaces

Related

More from this desk

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.

Oct 7·krebsonsecurity.com

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Jordanian teenager detained for leading ShinyHunters, a data theft and extortion group. FBI investigating extortion of Boeing subsidiary Jeppesen ForeFlight.

Oct 7·schneier.com

Apple’s Verified Photography System

Apple introduces a new system called 'Reference Image' to verify iPhone photos without tying them to specific devices or photographers.