Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

Asim Manizada publishes working local-root exploits for four Linux kernel bugs

Researcher Asim Manizada published working local-root exploits for four Linux kernel bugs on 18 September 2026. On hosts where containers or exposed services share one kernel, any compromised service can now become a lost node.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Asim Manizada publishes working local-root exploits for four Linux kernel bugs
Generated illustration

What happened

  • Manizada reported the bugs in mid-July and held them under coordinated disclosure so distributions could ship fixes before the exploits went out.
  • The 7.0 kernel series reached end of life on 27 June 2026, before the bugs were reported.
  • In a 29 September snapshot, Debian 12 bookworm's 6.1.187-1 kernel fixed DirtyAH6, PPPoEject and DiagSpill, with TUNderflow still the exception.

Why it matters

  • cost Each Proxmox host needs a window in which every VM and container is shut down or migrated, because the fixed kernel does nothing until the host reboots.
  • decision Teams on 7.0 have to confirm a vendor backport or move to a maintained branch such as 7.2.4, since waiting for an upstream 7.0 release is not an option.
  • constraint Comparing uname -r with the upstream list is unreliable on distribution kernels: bookworm's 6.1.187-1 sits below the 6.1.188 floor yet carries three of the four fixes.

A kernel privilege escalation usually waits for the next maintenance cycle because the attacker has to be on the box already. The dev.to post that collected these four bugs argues that this discount fails for self-hosted infrastructure. In its account, a compromised web app, a rogue package or an LXC container with a shared kernel each becomes full node ownership once a local root bug is available [13]. I think that is right, for one specific reason. Proxmox LXC containers run on the host kernel [8]. The same kernel these bugs attack is the one enforcing the boundary between container and host. Working proof-of-concept code is public for all four [4], so the second step of that chain needs no exploit development.

The post does not describe the bugs' internals or say whether any of them depends on a non-default config option. For per-CVE detail it points to the oss-security thread and Manizada's write-up [14]. Until that detail says otherwise, I would treat every node on an unfixed branch as exposed.

The 7.0 series has a timing problem. It reached end of life on 27 June 2026 [7]. Manizada reported the bugs in mid-July [5]. The branch closed a few weeks before the report, so no upstream 7.0 stable release was ever going to carry the fixes [18]. A 7.0 kernel has them only if its vendor backported them [7]. The only 7.x release on the upstream list is 7.2.4 [6].

Checking coverage takes more than reading a version string. Vendors backport fixes [7], so a distribution's version number does not map cleanly onto the upstream list. The post checked a status snapshot on 29 September against the Debian and Ubuntu trackers and the Proxmox kernel changelog [1]. In that snapshot, Debian 13 trixie fixed all four in linux 6.12.111-1, shipped as DSA-6528-1 [10]. That is two releases past the upstream 6.12.109 floor [19]. Debian 12 bookworm's 6.1.187-1 fixed DirtyAH6, PPPoEject and DiagSpill, with TUNderflow the exception [11]. That package sits one release below 6.1.188, the first upstream 6.1 release the post lists with all four fixes [20]. The post's advice is to cross-reference the running version against the distribution's security advisory [16].

Installing the package changes nothing on a running host. The old kernel stays in memory until a reboot [9]. The kernel in memory does not consult apt.

The post's sequence for Debian-family hosts, including Proxmox and Raspberry Pi OS, runs like this:

1. Record `uname -r` on every node [16]. 2. Run `sudo apt update && sudo apt full-upgrade -y`, and on Proxmox confirm the packages with `pveversion -v` [15]. 3. On Raspberry Pi OS Bookworm or newer, check `apt-cache policy linux-image-rpi-v8` (or `linux-image-rpi-2712`, depending on the board). Installed and Candidate should match [12]. 4. On Proxmox, shut down or migrate guests with `qm shutdown` and `pct shutdown` before rebooting the host [17]. 5. Reboot, run `uname -r` again and compare it with the distribution's advisory [16].

Step 3 matters because the package name changed. Bullseye and earlier shipped the kernel as `raspberrypi-kernel`, and Bookworm moved to Debian-style `linux-image-rpi-*` packages [12]. Querying the old name on a current install checks the wrong package [12].

What to watch

  • The Debian tracker entry for TUNderflow on bookworm, the one open gap in the post's 29 September snapshot.
  • The per-CVE detail in Manizada's write-up on required config options, the only basis for ruling any unpatched node out.
  • Backport advisories from vendors still shipping 7.0 kernels that name all four CVEs.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption30
Hype gap+10
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The post's distribution status snapshot was checked against the Debian security tracker, the Ubuntu CVE tracker and the Proxmox kernel changelog on 29 September 2026, and the post says to re-check before deciding a system is covered.

  2. [2]

    Four Linux kernel vulnerabilities went public on 18 September 2026: DirtyAH6 (CVE-2026-80844), PPPoEject (CVE-2026-68121), TUNderflow (CVE-2026-81000) and DiagSpill (CVE-2026-74469).

    ReportedSupportedSource: dev.to postView cited source
  3. [3]

    All four are local privilege escalation bugs: an attacker or malicious process with a foothold on the machine can escalate to root.

    ReportedSupportedSource: dev.to postView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 7, 2026

    Patch These Four Linux Kernel Local Root Vulns Now: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories