Linux LPE quartet and rsyslog DoS fix
Linux kernel local privilege escalations and a rsyslog denial-of-service fix dominated security disclosures. Post-embargo details arrived for four named flaws while a non-default logging module received a targeted update.
Four Linux kernel local root vulnerabilities disclosed
A quartet of Linux local root vulnerabilities known as DirtyAH6, PPPoEject, TUNderflow, and DiagSpill was disclosed on oss-security after embargo, accompanied by CVE identifiers such as CVE-2026-80844, commit hashes, prerequisites, and fixes already present in stable trees. The reports cover local privilege escalation paths in the kernel. Operators and distributors tracking kernel updates need the concrete details to assess exposure and confirm backports.
Rsyslog mmpstrucdata denial of service fixed
Rsyslog released version 8.2606.0 to address a denial-of-service condition in the non-default mmpstrucdata module when handling oversized structured data. The issue was announced on oss-security with the fix details. Sites that enable this module should update to avoid the crash condition.