OSG-SEC-2026-09-18 Linux multiple LPE vulns

Dear OSG Security Contacts,

Researchers disclosed three Linux kernel vulnerabilities that can potentially be used by a local unprivileged process to corrupt kernel memory and, under the required conditions, potentially escalate privileges. Public exploit code is available [1].

## WHAT ARE THE VULNERABILITIES:

CVE-2026-74469 – DiagSpill

A flaw was found in the Stream Control Transmission Protocol (SCTP) implementation within the Linux kernel. An integer overflow occurs when the transport_count for an association exceeds its 16-bit limit, causing it to wrap around to zero.

Impact: Kernel memory corruption / potential local privilege escalation. As per RedHat- “This memory corruption can result in a denial of service (DoS) due to system instability or crashes [4]”
Exploit preconditions:
SCTP support must be available.
sctp_diag support must be available.
No unprivileged user namespace or special capability is required for the demonstrated attack path.

CVE-2026-68121 – PPPoEject

A flaw was found in the Linux kernel's PPPoE (Point-to-Point Protocol over Ethernet) implementation. This vulnerability occurs because a pointer to network packet data is not updated after memory is reallocated, leading to the use of an outdated memory address.

Impact: Linux kernel memory corruption / potential local privilege escalation.

Exploit preconditions:

PPPoE support must be available.  
A lower network-device header callback must be capable of reallocating the socket buffer during dev\_hard\_header().  
The demonstrated unprivileged path requires unprivileged user/network namespaces, or equivalent CAP\_NET\_ADMIN control over an attacker-controlled network namespace.

CVE-2026-81000 – TUNderflow

A flaw was found in the Linux kernel's TUN/TAP driver. An integer underflow vulnerability exists in the tun_get_user() function when processing oversized headroom requests.

Impact: Kernel out-of-bounds write / potential local privilege escalation or denial of service.

Exploit preconditions:
TUN/TAP support must be available.
Open vSwitch must propagate an excessively large receive-headroom request to TUN/TAP.
The demonstrated unprivileged path requires unprivileged user/network namespaces, or equivalent CAP_NET_ADMIN control over an attacker-controlled network namespace.

## IMPACTED VERSIONS:

CVE-2026-68121 - RHEL 7,8,9, and 10 are affected [2].
CVE-2026-81000 - RHEL 7,8,9, and 10 are affected [3].
CVE-2026-74469 - RHEL 7,8,9, and 10 are affected [4].

## MITIGATION

CVE-2026-74469 – DiagSpill
Disable/remove SCTP support if SCTP is not required.
Ensure the sctp_diag module is not available/loadable where it is not needed.

CVE-2026-68121 – PPPoEject
If PPPoE functionality is not required, prevent the `pppoe` kernel module from loading to mitigate this vulnerability [2].
Disable unprivileged user namespaces/network namespaces where operationally feasible. The demonstrated corruption path requires unprivileged user namespaces and PPPoE support.

CVE-2026-81000 – TUNderflow
Disable/remove TUN/TAP support where it is not required.
Prevent unprivileged users from creating/controlling the required network namespaces.
Avoid exposing the vulnerable Open vSwitch → TUN/TAP networking path to unprivileged jobs.

Researchers have also discussed CVE-2026-80844 [1][5], a Linux kernel IPv6 vulnerability that may allow a local, low-privileged attacker to send a specially crafted packet, potentially resulting in a system crash or compromise. Red Hat has not yet published an assessment for this CVE.

## WHAT YOU SHOULD DO:

Apply the vendor kernel updates for affected RHEL systems. As an interim measure, verify whether SCTP/sctp_diag, PPPoE, and the relevant TUN/TAP/OVS networking paths are actually available and used on worker nodes.

Restricting unprivileged network namespaces reduces the demonstrated attack surface for CVE-2026-68121 and CVE-2026-81000, but does not address the demonstrated prerequisite model for CVE-2026-74469[1].

## REFERENCES
[1] https\://heyitsas.im/posts/lpe-quartet/
[2] https\://access.redhat.com/security/cve/cve-2026-68121
[3] https\://access.redhat.com/security/cve/cve-2026-81000
[4] https\://access.redhat.com/security/cve/cve-2026-74469
[5] https\://nvd.nist.gov/vuln/detail/cve-2026-80844