< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Linux kernel vulnerabilities face active exploitation and public exploits

Multiple vulnerabilities in the Linux kernel are being actively exploited or have had public proof-of-concept exploits released.

CISA has added three specific vulnerabilities (CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964) to its Known Exploited Vulnerabilities (KEV) catalog. While patches for these issues have been available since 2025, the inclusion in the catalog indicates they are being actively used in attacks, primarily targeting systems that have not been rebooted or updated following the release of the fixes.

Separately, security researcher Asim Viladi Oglu Manizada has released public exploits for four local root vulnerabilities: DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469). These flaws, some of which reportedly existed in the code for up to 21 years, allow local attackers to escalate privileges to the system level. While some vulnerabilities require unprivileged user namespaces, DiagSpill can be exploited without specific preconditions. Experts note that remote root takeover remains theoretical, with remote exploitation currently limited to causing system crashes.

Entities

Asim Viladi Oglu Manizada · CISA · Linux kernel · NIST · Red Hat