Credit where it's due: this is an excellent announcement (except for the bugs of course):
* List of fix commits. * List of stable versions containing the fix. * Detailed pre-requisites for exploitation. * Concrete list of affected subsystems/modules to apply mitigations. * Clear list of vulnerable versions. * No Markdown, no extraneous LLM product placement, just the relevant bits in clear plaintext. With LPEs coming out every few weeks having this level of informative posts is a great help. -valtteri On Fri, Sep 18, 2026 at 06:15:07AM +0000, manizada wrote: > Hi folks, > > Emailing here now that the embargo agreed upon with linux-distros@ has > expired. > > Flagging four local root vulnerabilities in the Linux kernel, originally > reported to [email protected] and the relevant maintainers in > mid-July: > > DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject > (CVE-2026-68121), and DiagSpill (CVE-2026-74469). [...]
