Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-80844 — Research repository for CVE-2026-80844 (DirtyAH6), a Linux kernel IPv6 AH6/XFRM local privilege escalation, with PoC, root-cause and patch analysis. | Kitploit
도구/GitHubGitHub/0xblackash/cve-2026-80844
Privilege EscalationVulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary Exploitation
GitHub0xblackash/cve-2026-80844

CVE-2026-80844

Research repository for CVE-2026-80844 (DirtyAH6), a Linux kernel IPv6 AH6/XFRM local privilege escalation, with PoC, root-cause and patch analysis.

저장소 보기
12711일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

🔥 CVE-2026-80844 - DirtyAH6

Gemini_Generated_Image_9hzttu9hzttu9hzt

Linux Kernel IPv6 AH6 Local Privilege Escalation

CVE-2026-80844 is a Linux kernel vulnerability affecting the IPv6 Authentication Header (AH6) / XFRM subsystem.

The vulnerability is caused by insufficient validation of the IPv6 Routing Header segments_left field, potentially resulting in an out-of-bounds memory operation and kernel memory corruption.


⚠️ Disclaimer

This repository is intended for authorized security research, vulnerability analysis, CTFs, and defensive testing only.

Do not use this research against systems you do not own or have explicit permission to test.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-80844
CodenameDirtyAH6
ComponentLinux Kernel
SubsystemIPv6 / XFRM / AH6
Vulnerability TypeLocal Privilege Escalation
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
CVSS v3.17.8 — High
Affected Codenet/ipv6/ah6.c
StatusPatched

🧬 Vulnerability Description

The vulnerability exists in the IPv6 AH6 processing path.

The affected code performs routing-header manipulation through:

net/ipv6/ah6.c

Specifically, the vulnerable logic involves:

ipv6_rearrange_rthdr()

The function failed to adequately validate the relationship between:

hdrlen

and:

segments_left

An attacker capable of supplying a specially crafted IPv6 packet can therefore cause the kernel to operate on memory outside the expected routing-header boundaries.

This can lead to:

Malformed IPv6 packet
        │
        ▼
AH6 / XFRM processing
        │
        ▼
Invalid routing-header state
        │
        ▼
Out-of-bounds memory operation
        │
        ▼
Kernel memory corruption
        │
        ▼
Potential privilege escalation

🔬 Root Cause

The fundamental issue is insufficient validation of the IPv6 Routing Header segments_left value.

Conceptually, the vulnerable condition can be represented as:

segments_left > available routing-header addresses

The kernel must ensure that the number of segments requested by the routing header is consistent with the actual header length before manipulating the associated address data.

Without that validation, subsequent memory operations can operate beyond the valid buffer boundaries.


💥 Security Impact

Successful exploitation may allow an attacker with the required local capabilities/environment to corrupt kernel memory.

Potential consequences include:

  • Kernel memory corruption
  • Kernel crash
  • Denial of service
  • Potential arbitrary kernel code execution
  • Local privilege escalation
  • Potential transition from an unprivileged context to kernel/root privileges

The exact exploitability depends on the kernel configuration, available namespaces/capabilities, and other environmental conditions.


🧪 Technical Analysis

Vulnerable Component

net/ipv6/ah6.c

Relevant processing:

AH6
 └── IPv6 Routing Header
      └── ipv6_rearrange_rthdr()

The problematic scenario involves inconsistent routing-header metadata.

For example, conceptually:

hdrlen        → describes a limited number of addresses
segments_left → claims more addresses than are available

This mismatch must be rejected before the kernel performs address rearrangement.


🩹 Patch Analysis

The upstream fix introduces validation for the Routing Header's segments_left value before the kernel performs the vulnerable operation.

The associated upstream commit is:

7bad4bda74dc4713f398d3b7624ff05478e3a568

xfrm: ah6: validate routing header segments_left

The security fix can be summarized as:

Before:
    Trust segments_left
          ↓
    Rearrange addresses
          ↓
    Potential OOB access

After:
    Validate segments_left
          ↓
    Reject malformed header
          ↓
    Safe AH6 processing

🖥️ Affected Kernel Versions

Affected versions depend on the upstream and vendor backport history.

Users should verify their distribution's security advisory rather than relying only on the upstream version number.

Examples of patched upstream stable releases include:

Kernel branchPatched release
5.105.10.270
5.155.15.221
6.16.1.188
6.66.6.157
6.126.12.109
6.186.18.50
7.27.2.4

🔎 Detection

Check the running kernel:

uname -a

or:

uname -r

Check detailed kernel information:

cat /proc/version

For Debian/Kali-based systems:

apt-cache policy linux-image-amd64

For RPM-based systems:

rpm -q kernel

Distribution kernels frequently backport security fixes without changing the upstream version in an obvious way. Always check the vendor advisory/changelog.


🛡️ Mitigation

The primary mitigation is to upgrade to a kernel containing the security fix.

Debian/Kali:

sudo apt update
sudo apt full-upgrade

Then reboot:

sudo reboot

Verify:

uname -r

For production systems, consult the Linux distribution's official security advisory before applying kernel updates.


🧰 Research Environment

Recommended isolated environment:

Host
 │
 ├── Kali Linux
 │
 └── Vulnerable Linux VM
       │
       ├── Debug kernel
       ├── IPv6 enabled
       ├── AH6/XFRM support
       └── Kernel symbols

Useful debugging tools:

gdb
gef
pwndbg
crash
dmesg
pahole
objdump
readelf

Kernel debugging:

sudo dmesg -w

Inspect kernel symbols:

cat /proc/kallsyms

📂 Repository Structure

CVE-2026-80844-DirtyAH6/
│
├── README.md
│
├── exploit/
│   ├── poc.c
│   └── Makefile
│
├── analysis/
│   ├── vulnerability.md
│   ├── root-cause.md
│   └── patch-analysis.md
│
├── kernel/
│   ├── vulnerable.patch
│   └── fixed.patch
│
├── docs/
│   └── research-notes.md
│
├── screenshots/
│
└── LICENSE

🧪 Proof of Concept

PoC material should only be executed inside an isolated laboratory environment.

The research implementation focuses on demonstrating the malformed IPv6 Routing Header condition and observing the resulting kernel behavior.

Expected research workflow:

도구 다운로드