NoticiasNews

Cuatro fallos del kernel de Linux con exploits públicos: root local en cualquier servidor que no haya actualizadoFour Linux Kernel Flaws With Public Exploits: Local Root on Any Server That Has Not Been Updated

2026-09-20

El investigador Asim Manizada publicó el 18 de septiembre un informe técnico con código de explotación funcional para cuatro fallos del kernel de Linux que permiten a un usuario local escalar hasta root, el nivel máximo de acceso en una máquina. La publicación se hizo tras un período de retención coordinado con las distribuciones, de modo que las correcciones salieran primero. Manizada reportó los hallazgos al equipo de seguridad del kernel a mediados de julio.

La frase que importa: los cuatro fallos ya están corregidos. Un sistema con kernel al día no está afectado. Lo que cambió el 18 de septiembre es que el código para aprovecharlos es público, y eso reordena las prioridades de cualquier equipo que administre servidores con kernels antiguos.

Qué son los cuatro fallos

  • DirtyAH6 (CVE-2026-80844), en el código de IPsec que maneja la cabecera de autenticación de IPv6. El código confiaba en un campo de la cabecera de enrutamiento sin verificarlo contra el número de direcciones presentes.
  • TUNderflow (CVE-2026-81000), en los dispositivos de red virtuales TUN y TAP. Un mismo valor se usaba como espacio sobrante y como tamaño, y un valor excesivo hacía que el cálculo se desbordara.
  • PPPoEject (CVE-2026-68121), en el código de PPP sobre Ethernet. Un uso después de liberación clásico: se conservaba un puntero a un búfer de red mientras se llamaba a una rutina que podía liberarlo y moverlo.
  • DiagSpill (CVE-2026-74469), en el código de reporte de SCTP. Un contador de 16 bits se desbordaba al llegar al extremo 65,536, y el código terminaba copiando cerca de 8 MiB de datos fuera de su búfer.

Los cuatro son errores de seguridad de memoria en distintas partes del código de red del kernel, y los descuidos subyacentes tienen entre 10 y 21 años de antigüedad.

La condición que decide si usted está expuesto

Tres de los cuatro solo son alcanzables por un usuario común cuando están habilitados los user namespaces sin privilegios, la función de Linux que permite a un usuario normal actuar como root dentro de un espacio aislado. Muchas distribuciones los habilitan por defecto, y ahí es donde el atacante obtiene los privilegios de red que los exploits necesitan.

DiagSpill es la excepción: no requiere namespaces ni privilegios especiales, siempre que el módulo de red SCTP esté disponible en el sistema.

Dos de los fallos, DirtyAH6 y DiagSpill, pueden dispararse por red, pero en escenarios estrechos y principalmente para provocar una caída del sistema, no para obtener root. Manizada logró root remoto con DirtyAH6 únicamente en su propio laboratorio y tras preparar la memoria del objetivo; describió hacerlo desde una posición puramente remota como extremadamente difícil. El investigador también señaló que, en teoría, los fallos podrían permitir escapar de un contenedor, aunque no construyó una prueba de ello.

Qué hacer esta semana

Actualizar a un kernel que lleve las cuatro correcciones. Las primeras versiones estables del proyecto principal que incluyen el conjunto completo son 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 y 7.2.4. La advertencia práctica es que casi nadie corre el kernel del proyecto principal: la mayoría usa el de su distribución, con numeración propia y calendario propio. Hay que verificar el aviso de seguridad de Debian, Ubuntu, Red Hat o SUSE y confirmar que la actualización publicada incluye los cuatro, en lugar de comparar números de versión.

Si no se puede parchear de inmediato, dos medidas reducen el riesgo: desactivar los user namespaces sin privilegios, lo que cierra la vía del usuario común a tres de los cuatro fallos, y desactivar las funciones afectadas que no se usen, es decir AH6, TUN/TAP, PPPoE y SCTP. Ninguna de las dos detiene a un proceso que ya tenga privilegios de administración de red, y el propio investigador recomienda parchear en lugar de desactivar, porque pueden existir otras rutas hacia los mismos fallos.

Hasta ahora no hay reportes de uso de estos cuatro fallos en ataques reales. Los exploits publicados están ajustados a compilaciones específicas del kernel y pueden hacer caer la máquina, por lo que están pensados para sistemas de prueba aislados.

El dato que merece atención aparte

Manizada declaró haber encontrado los cuatro fallos con un proceso asistido por IA que construye un mapa de cómo el kernel maneja la memoria y razona sobre su disposición. La corrección de DirtyAH6 lo deja registrado: el commit incluye una línea de reconocimiento a su herramienta. Es el último episodio de una racha de fallos de escalada de privilegios en el kernel divulgados durante 2026, varios de ellos hallados con ayuda de modelos de lenguaje. La superficie de auditoría del software de base está creciendo más rápido que los ciclos de parcheo de muchas organizaciones.

Lo que esto significa para su operación

En TEKFENIX desarrollamos software empresarial a medida y productos SaaS para el Caribe y Latinoamérica, y este tipo de aviso define nuestro trabajo de operación tanto como el de desarrollo. La escalada local de privilegios importa sobre todo donde varios inquilinos comparten infraestructura, que es exactamente el escenario de un SaaS: por eso Nexturno, Servigo365 y CumplimientoControl se sostienen sobre inventario actualizado de versiones, ventanas de parcheo definidas y aislamiento entre clientes. Si su organización no tiene claro qué kernel corre cada uno de sus servidores ni cuándo se actualizó por última vez, esa es la primera conversación, antes que cualquier CVE puntual. Podemos ayudarle a ordenarla.

Researcher Asim Manizada published a technical write-up on 18 September with working exploit code for four Linux kernel flaws that let a local user escalate to root, the highest level of access on a machine. Publication followed a coordinated hold with Linux distributions so the fixes could be released first. Manizada reported the findings to the Linux kernel security team in mid-July.

The sentence that matters: all four flaws are already fixed. A system running an up-to-date kernel is not affected. What changed on 18 September is that the code to exploit them is public, and that reorders priorities for any team running servers on older kernels.

What the four flaws are

  • DirtyAH6 (CVE-2026-80844), in the IPsec code handling the IPv6 Authentication Header. The code trusted a routing-header field without verifying it against the number of addresses present.
  • TUNderflow (CVE-2026-81000), in the TUN and TAP virtual network devices. A single value served both as spare space and as a size, and an oversized value made the calculation wrap around.
  • PPPoEject (CVE-2026-68121), in the PPP over Ethernet code. A classic use-after-free: a pointer into a network buffer was kept while calling a device routine that could free and move it.
  • DiagSpill (CVE-2026-74469), in the SCTP reporting code. A 16-bit counter wrapped at the 65,536th endpoint, and the code ended up copying roughly 8 MiB of data past the end of its buffer.

All four are memory-safety bugs in different parts of the kernel networking code, and the underlying mistakes range from 10 to 21 years old.

The condition that decides whether you are exposed

Three of the four are reachable by an ordinary user only when unprivileged user namespaces are enabled, the Linux feature that lets a normal user act as root inside a private sandbox. Many distributions enable them by default, and that is where an attacker gains the network privileges the exploits require.

DiagSpill is the exception: it needs no namespaces or special privileges, as long as the SCTP networking module is available on the system.

Two of the flaws, DirtyAH6 and DiagSpill, can be triggered over the network, but only in narrow cases and mainly to crash the host, not to obtain root. Manizada reached remote root with DirtyAH6 only in his own lab and only after shaping memory on the target first; he described doing so from a purely remote position as extremely difficult. He also noted that, in theory, the flaws could allow a container escape, though he did not build one.

What to do this week

Update to a kernel carrying all four fixes. The first stable releases from the main kernel project with the complete set are 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4. The practical caveat is that almost nobody runs the mainline kernel: most people run their distribution kernel, with its own numbering and its own schedule. Check the security advisory from Debian, Ubuntu, Red Hat or SUSE and confirm the published update includes all four, rather than matching version numbers.

If patching right away is not possible, two steps reduce the risk: turn off unprivileged user namespaces, which closes the ordinary-user path to three of the four flaws, and turn off affected features you do not use, namely AH6, TUN/TAP, PPPoE and SCTP. Neither stops a process that already holds network-admin privileges, and the researcher himself recommends patching over disabling, because other paths to the same flaws may exist.

So far there are no reports of these four being used in real-world attacks. The published exploits are tuned to specific kernel builds and can crash a machine, so they are meant for isolated test systems.

The detail that deserves separate attention

Manizada said he found all four flaws with an AI-assisted process that builds a map of how the kernel handles memory and reasons about its layout. The DirtyAH6 fix records it: the commit includes a line crediting his custom tooling. This is the latest in a run of kernel privilege escalation flaws disclosed through 2026, several of them found with help from language models. The audit surface of foundational software is growing faster than many organisations patch.

What this means for your operation

At TEKFENIX we build custom enterprise software and vertical SaaS products for the Caribbean and Latin America, and an advisory like this shapes our operations work as much as our development work. Local privilege escalation matters most where several tenants share infrastructure, which is precisely the SaaS scenario: that is why Nexturno, Servigo365 and CumplimientoControl rest on a current inventory of versions, defined patch windows and isolation between customers. If your organisation cannot say which kernel each of its servers runs or when it was last updated, that is the first conversation to have, ahead of any individual CVE. We can help you put it in order.

← Volver al blog← Back to blog