A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill

2 points by buherator


dzwdz

If the target is acting as an IPv6 router/gateway and adds AH in transport mode, the bug can be turned into a remote crash/DoS. With on-target memory grooming, I was able to turn it into remote root in a lab environment.

Remote-only grooming to root is theoretically possible, but looks extremely difficult.

Wow. I hope that in a few years I'll stumble upon a blog post about someone actually successfully exploiting this :p