A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
2 points by buherator
2 points by buherator
If the target is acting as an IPv6 router/gateway and adds AH in transport mode, the bug can be turned into a remote crash/DoS. With on-target memory grooming, I was able to turn it into remote root in a lab environment.
Remote-only grooming to root is theoretically possible, but looks extremely difficult.
Wow. I hope that in a few years I'll stumble upon a blog post about someone actually successfully exploiting this :p