Critical vulnerabilities in the Linux kernel, KVM, Exim, Unbound, Ghostscript, and Suricata

Several recently discovered vulnerabilities allow for root access within the system or achieve remote code execution.

  • Details have been revealed about four vulnerabilities in the Linux kernel that allow a non-privileged local user to execute code with root privileges. The issues have been resolved in updates for Linux kernels 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, and 7.2.4. Exploits for all vulnerabilities have been prepared, with demonstrations taking place in Fedora 43/44 and Ubuntu 24.04. To exploit the first three vulnerabilities, user namespace creation capability or CAP_NET_ADMIN rights are required, as well as support for subsystems where the vulnerabilities exist (AH6/XFRM, TUN, PPPoE, and SCTP).
    • DirtyAH6 (CVE-2026-80844, exploit) — a buffer overflow in the IPsec AH (Authentication Header) handler due to lack of validation on header-specified values. In addition to local execution of the attack, the vulnerability may theoretically be exploited remotely under specific conditions.
    • TUNderflow (CVE-2026-81000, exploit) — out-of-bounds write when parsing an incorrectly formatted TUN packet.
    • PPPoEject (CVE-2026-68121, exploit) — accessing already freed memory in the PPPoE driver.
    • DiagSpill (CVE-2026-74469, exploit) — buffer overflow in SCTP protocol diagnostics. In addition to local execution of the attack, the vulnerability may theoretically be exploited remotely under specific conditions.
  • Vulnerability (CVE-2026-89775) in the hypervisor KVM, allowing access to the host environment from the guest system. If unprivileged users have access to the device /dev/kvm (by default in RHEL), the vulnerability can also be exploited to escalate privileges in the system. The issue only manifests on ARM64 architecture systems with nested virtualization support enabled. The vulnerability is caused by the size calculation procedure returning '0', implying that the size is unknown, while the memory page deallocation function treats '0' as an actual value and does not clear the memory pages.
  • In the mail release server Exim 4.100.1 has fixed 4 vulnerabilities: reading data from outside the buffer and using uninitialized data in the Proxy protocol implementation; accessing memory after it has been freed in TLS-on-connect when using GnuTLS; message injection into another stream (SMTP smuggling).
  • The Ghostscript package 10.08.0 has addressed a vulnerability (CVE-2026-39919) caused by a buffer overflow in the code for parsing JPEG 2000 format when incorrect subsampling values are specified. This issue can lead to code execution when processing specially crafted PDF files with embedded JPEG 2000 images in Ghostscript. The risk of this vulnerability is heightened as Ghostscript is invoked during thumbnail generation on the desktop, during background data indexing, and when converting images. In many cases, to successfully exploit it, it is sufficient to simply upload a file with the exploit or view a directory containing it in Nautilus. Vulnerabilities in Ghostscript can also be exploited via image handlers based on the ImageMagick and GraphicsMagick packages by passing a JPEG or PNG file that contains PostScript code instead of an image (such a file will be processed by Ghostscript, as the MIME type is recognized by content rather than relying on the extension). The issue has been resolved in Ghostscript 10.08.0.
  • In the DNS server Unbound 1.26.1, 9 vulnerabilities have been addressed, among them the CVE-2026-81642 issue, which leads to buffer overflow when processing certain DNSKEY records. The vulnerability can be exploited for remote code execution on server. Other fixes include: buffer overflow in the DNSSEC handling code, memory corruption in the CNAME handler, and accessing already freed memory in the DoQ and DoH code.
  • The Suricata intrusion detection and prevention system version 8.0.7 has fixed 67 vulnerabilities, with two marked as critical. Details of the issues are not yet disclosed, but given their severity, the vulnerabilities allow for remote code execution when processing specially crafted traffic.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster