Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-80844 — Research repository for CVE-2026-80844 (DirtyAH6), a Linux kernel IPv6 AH6/XFRM local privilege escalation, with PoC, root-cause and patch analysis. | Kitploit
Herramientas/GitHubGitHub/0xblackash/cve-2026-80844
Privilege EscalationVulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary Exploitation
GitHub0xblackash/cve-2026-80844

CVE-2026-80844

Research repository for CVE-2026-80844 (DirtyAH6), a Linux kernel IPv6 AH6/XFRM local privilege escalation, with PoC, root-cause and patch analysis.

Ver Repositorio
127hace 11 díasAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

🔥 CVE-2026-80844 - DirtyAH6

Gemini_Generated_Image_9hzttu9hzttu9hzt

Linux Kernel IPv6 AH6 Local Privilege Escalation

CVE-2026-80844 is a Linux kernel vulnerability affecting the IPv6 Authentication Header (AH6) / XFRM subsystem.

The vulnerability is caused by insufficient validation of the IPv6 Routing Header segments_left field, potentially resulting in an out-of-bounds memory operation and kernel memory corruption.


⚠️ Disclaimer

This repository is intended for authorized security research, vulnerability analysis, CTFs, and defensive testing only.

Do not use this research against systems you do not own or have explicit permission to test.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-80844
CodenameDirtyAH6
ComponentLinux Kernel
SubsystemIPv6 / XFRM / AH6
Vulnerability TypeLocal Privilege Escalation
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
CVSS v3.17.8 — High
Affected Codenet/ipv6/ah6.c
StatusPatched

🧬 Vulnerability Description

The vulnerability exists in the IPv6 AH6 processing path.

The affected code performs routing-header manipulation through:

net/ipv6/ah6.c

Specifically, the vulnerable logic involves:

ipv6_rearrange_rthdr()

The function failed to adequately validate the relationship between:

hdrlen

and:

segments_left

An attacker capable of supplying a specially crafted IPv6 packet can therefore cause the kernel to operate on memory outside the expected routing-header boundaries.

This can lead to:

Malformed IPv6 packet
        │
        ▼
AH6 / XFRM processing
        │
        ▼
Invalid routing-header state
        │
        ▼
Out-of-bounds memory operation
        │
        ▼
Kernel memory corruption
        │
        ▼
Potential privilege escalation

🔬 Root Cause

The fundamental issue is insufficient validation of the IPv6 Routing Header segments_left value.

Conceptually, the vulnerable condition can be represented as:

segments_left > available routing-header addresses

The kernel must ensure that the number of segments requested by the routing header is consistent with the actual header length before manipulating the associated address data.

Without that validation, subsequent memory operations can operate beyond the valid buffer boundaries.


💥 Security Impact

Successful exploitation may allow an attacker with the required local capabilities/environment to corrupt kernel memory.

Potential consequences include:

  • Kernel memory corruption
  • Kernel crash
  • Denial of service
  • Potential arbitrary kernel code execution
  • Local privilege escalation
  • Potential transition from an unprivileged context to kernel/root privileges

The exact exploitability depends on the kernel configuration, available namespaces/capabilities, and other environmental conditions.


🧪 Technical Analysis

Vulnerable Component

net/ipv6/ah6.c

Relevant processing:

AH6
 └── IPv6 Routing Header
      └── ipv6_rearrange_rthdr()

The problematic scenario involves inconsistent routing-header metadata.

For example, conceptually:

hdrlen        → describes a limited number of addresses
segments_left → claims more addresses than are available

This mismatch must be rejected before the kernel performs address rearrangement.


🩹 Patch Analysis

The upstream fix introduces validation for the Routing Header's segments_left value before the kernel performs the vulnerable operation.

The associated upstream commit is:

7bad4bda74dc4713f398d3b7624ff05478e3a568

xfrm: ah6: validate routing header segments_left

The security fix can be summarized as:

Before:
    Trust segments_left
          ↓
    Rearrange addresses
          ↓
    Potential OOB access

After:
    Validate segments_left
          ↓
    Reject malformed header
          ↓
    Safe AH6 processing

🖥️ Affected Kernel Versions

Affected versions depend on the upstream and vendor backport history.

Users should verify their distribution's security advisory rather than relying only on the upstream version number.

Examples of patched upstream stable releases include:

Kernel branchPatched release
5.105.10.270
5.155.15.221
6.16.1.188
6.66.6.157
6.126.12.109
6.186.18.50
7.27.2.4

🔎 Detection

Check the running kernel:

uname -a

or:

uname -r

Check detailed kernel information:

cat /proc/version

For Debian/Kali-based systems:

apt-cache policy linux-image-amd64

For RPM-based systems:

rpm -q kernel

Distribution kernels frequently backport security fixes without changing the upstream version in an obvious way. Always check the vendor advisory/changelog.


🛡️ Mitigation

The primary mitigation is to upgrade to a kernel containing the security fix.

Debian/Kali:

sudo apt update
sudo apt full-upgrade

Then reboot:

sudo reboot

Verify:

uname -r

For production systems, consult the Linux distribution's official security advisory before applying kernel updates.


🧰 Research Environment

Recommended isolated environment:

Host
 │
 ├── Kali Linux
 │
 └── Vulnerable Linux VM
       │
       ├── Debug kernel
       ├── IPv6 enabled
       ├── AH6/XFRM support
       └── Kernel symbols

Useful debugging tools:

gdb
gef
pwndbg
crash
dmesg
pahole
objdump
readelf

Kernel debugging:

sudo dmesg -w

Inspect kernel symbols:

cat /proc/kallsyms

📂 Repository Structure

CVE-2026-80844-DirtyAH6/
│
├── README.md
│
├── exploit/
│   ├── poc.c
│   └── Makefile
│
├── analysis/
│   ├── vulnerability.md
│   ├── root-cause.md
│   └── patch-analysis.md
│
├── kernel/
│   ├── vulnerable.patch
│   └── fixed.patch
│
├── docs/
│   └── research-notes.md
│
├── screenshots/
│
└── LICENSE

🧪 Proof of Concept

PoC material should only be executed inside an isolated laboratory environment.

The research implementation focuses on demonstrating the malformed IPv6 Routing Header condition and observing the resulting kernel behavior.

Expected research workflow:

Descargar herramienta