On September 18, 2026, Linux server administrators got two pieces of bad news at once. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-39964 (a kernel race condition) and CVE-2026-53266 (a kernel out-of-bounds write) to its Known Exploited Vulnerabilities catalog "based on evidence of active exploitation". The same day, security researcher Asim Manizada published working exploit code for four local privilege escalation bugs in the kernel.
Where the Four Bugs Live
- DirtyAH6 (CVE-2026-80844): the IPsec AH6/XFRM path. Exploitation needs unprivileged user namespaces, with CAP_NET_ADMIN and CAP_NET_RAW inside one.
- TUNderflow (CVE-2026-81000): TUN/TAP virtual devices. Also needs unprivileged user namespaces plus CAP_NET_ADMIN.
- PPPoEject (CVE-2026-68121): PPPoE. Same prerequisites.
- DiagSpill (CVE-2026-74469): SCTP's sctp_diag. No special prerequisites — the one to prioritise.
All four let an ordinary local user become root. The researcher lists the first stable kernels containing all four fixes as 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4.
What "Local Privilege Escalation" Means for a VPS
"Local" is not reassuring. The value of a local root bug is that it amplifies other bugs: a low-privilege command execution in a web app becomes root in one more step, and shared build machines, multi-user dev boxes and container hosts are hit most directly. As we noted in our report on CISA's September 3 additions, attackers who get in reliably go for persistence and cryptomining next — and root makes the clean-up much harder.
Work Through It in This Order
- Check the running kernel with
uname -r, then read your distribution's security advisories. Distro kernels backport fixes, so their version numbers don't map one-to-one onto upstream — the distro advisory is what counts. - Reboot after upgrading (or confirm your live-patching service covers these CVEs). Installing the package without a reboot leaves the old kernel running.
- If you can't reboot yet, apply the researcher's mitigations: disabling unprivileged user namespaces removes the ordinary-user path to the first three (
kernel.unprivileged_userns_cloneon Debian/Ubuntu,user.max_user_namespacesgenerally) but does not stop DiagSpill; unused AH6, TUN, PPPoE and SCTP modules can be disabled. Turning off user namespaces can break rootless containers and similar features, so check your dependencies first. - Basics beyond patching: hardening with ufw and SSH key login narrows the way in, and if you suspect a machine was already exploited, follow the post-compromise checklist rather than patching and moving on.
When choosing a system, long-term-support releases get kernel security updates faster and with better documentation; choosing a VPS operating system compares the options.