Security researcher Asim Manizada published working exploit code on 18 September for four Linux kernel flaws that let a local user gain root access, The Hacker News reported. The flaws are named DirtyAH6, TUNderflow, PPPoEject and DiagSpill. The disclosure followed coordination with kernel maintainers and Linux distributions.
Background
A local privilege-escalation flaw does not let an attacker in from the internet. It lets someone who already runs code on a machine, such as a malicious app or a compromised account, become the administrator. On a desktop or a shared system, that turns a small foothold into full control [1].
What the report describes
The flaws are tracked as CVE-2026-80844 (DirtyAH6, in IPsec AH6), CVE-2026-81000 (TUNderflow, in TUN/TAP virtual devices), CVE-2026-68121 (PPPoEject, in PPPoE) and CVE-2026-74469 (DiagSpill, in SCTP diagnostics). All four are memory-safety bugs in the kernel's networking code, and the report says the underlying issues are between 10 and 21 years old. DiagSpill involves a 16-bit counter of connection endpoints that wraps to zero at the 65,536th endpoint [1].
DirtyAH6, TUNderflow and PPPoEject need unprivileged user namespaces. DiagSpill does not need them or any special privilege, provided the SCTP module is available. The first stable kernels containing all four fixes are 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4 [1].
Manizada says he found the flaws with an AI-assisted process that maps how the kernel handles memory and reasons about its layout, and the kernel commit for DirtyAH6 carries an Assisted-by credit to his tooling. The report says no exploitation in real attacks has been confirmed [1].
Implications for Linux and Mac users
The flaws are in the Linux kernel, so the exposed group is people running Linux on desktops, laptops, development machines and shared systems on kernels older than the listed releases. macOS uses a different kernel and is not mentioned in the report [1].
Recommendations
- Install the distribution’s latest kernel update and restart, and check that the running kernel is at least one of the versions listed for its series.
- Where patching must wait, the report lists disabling unprivileged user namespaces, which closes three of the four flaws but not DiagSpill.
- The report also lists disabling AH6, TUN/TAP, PPPoE and SCTP where they are not needed.
- Keep untrusted users and untrusted code off shared systems until updated.
Relevance to FireAI
FireAI does not run on Linux and does not patch kernels, so this story is background for Mac users, not a FireAI use case. The general lesson holds on every platform: privilege escalation needs code already running, and a firewall that asks before an unknown app connects addresses a different stage, the connection. It does not stop local escalation.
Limitations
The report does not state when each fix reached individual distributions, which desktop environments are most exposed, or whether the exploit code works unchanged on distribution kernels. It gives no count of affected machines. Manizada's statement that this batch likely ends the public phase of his AI-assisted bug hunting is his own [1].
Try FireAI, by HisnLabs free for 17 days.