Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-80844 — Research repository for CVE-2026-80844 (DirtyAH6), a Linux kernel IPv6 AH6/XFRM local privilege escalation, with PoC, root-cause and patch analysis. | Kitploit
工具/GitHubGitHub/0xblackash/cve-2026-80844
Privilege EscalationVulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary Exploitation
GitHub0xblackash/cve-2026-80844

CVE-2026-80844

Research repository for CVE-2026-80844 (DirtyAH6), a Linux kernel IPv6 AH6/XFRM local privilege escalation, with PoC, root-cause and patch analysis.

查看仓库
12711天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

🔥 CVE-2026-80844 - DirtyAH6

Gemini_Generated_Image_9hzttu9hzttu9hzt

Linux Kernel IPv6 AH6 Local Privilege Escalation

CVE-2026-80844 is a Linux kernel vulnerability affecting the IPv6 Authentication Header (AH6) / XFRM subsystem.

The vulnerability is caused by insufficient validation of the IPv6 Routing Header segments_left field, potentially resulting in an out-of-bounds memory operation and kernel memory corruption.


⚠️ Disclaimer

This repository is intended for authorized security research, vulnerability analysis, CTFs, and defensive testing only.

Do not use this research against systems you do not own or have explicit permission to test.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-80844
CodenameDirtyAH6
ComponentLinux Kernel
SubsystemIPv6 / XFRM / AH6
Vulnerability TypeLocal Privilege Escalation
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
CVSS v3.17.8 — High
Affected Codenet/ipv6/ah6.c
StatusPatched

🧬 Vulnerability Description

The vulnerability exists in the IPv6 AH6 processing path.

The affected code performs routing-header manipulation through:

net/ipv6/ah6.c

Specifically, the vulnerable logic involves:

ipv6_rearrange_rthdr()

The function failed to adequately validate the relationship between:

hdrlen

and:

segments_left

An attacker capable of supplying a specially crafted IPv6 packet can therefore cause the kernel to operate on memory outside the expected routing-header boundaries.

This can lead to:

Malformed IPv6 packet
        │
        ▼
AH6 / XFRM processing
        │
        ▼
Invalid routing-header state
        │
        ▼
Out-of-bounds memory operation
        │
        ▼
Kernel memory corruption
        │
        ▼
Potential privilege escalation

🔬 Root Cause

The fundamental issue is insufficient validation of the IPv6 Routing Header segments_left value.

Conceptually, the vulnerable condition can be represented as:

segments_left > available routing-header addresses

The kernel must ensure that the number of segments requested by the routing header is consistent with the actual header length before manipulating the associated address data.

Without that validation, subsequent memory operations can operate beyond the valid buffer boundaries.


💥 Security Impact

Successful exploitation may allow an attacker with the required local capabilities/environment to corrupt kernel memory.

Potential consequences include:

  • Kernel memory corruption
  • Kernel crash
  • Denial of service
  • Potential arbitrary kernel code execution
  • Local privilege escalation
  • Potential transition from an unprivileged context to kernel/root privileges

The exact exploitability depends on the kernel configuration, available namespaces/capabilities, and other environmental conditions.


🧪 Technical Analysis

Vulnerable Component

net/ipv6/ah6.c

Relevant processing:

AH6
 └── IPv6 Routing Header
      └── ipv6_rearrange_rthdr()

The problematic scenario involves inconsistent routing-header metadata.

For example, conceptually:

hdrlen        → describes a limited number of addresses
segments_left → claims more addresses than are available

This mismatch must be rejected before the kernel performs address rearrangement.


🩹 Patch Analysis

The upstream fix introduces validation for the Routing Header's segments_left value before the kernel performs the vulnerable operation.

The associated upstream commit is:

7bad4bda74dc4713f398d3b7624ff05478e3a568

xfrm: ah6: validate routing header segments_left

The security fix can be summarized as:

Before:
    Trust segments_left
          ↓
    Rearrange addresses
          ↓
    Potential OOB access

After:
    Validate segments_left
          ↓
    Reject malformed header
          ↓
    Safe AH6 processing

🖥️ Affected Kernel Versions

Affected versions depend on the upstream and vendor backport history.

Users should verify their distribution's security advisory rather than relying only on the upstream version number.

Examples of patched upstream stable releases include:

Kernel branchPatched release
5.105.10.270
5.155.15.221
6.16.1.188
6.66.6.157
6.126.12.109
6.186.18.50
7.27.2.4

🔎 Detection

Check the running kernel:

uname -a

or:

uname -r

Check detailed kernel information:

cat /proc/version

For Debian/Kali-based systems:

apt-cache policy linux-image-amd64

For RPM-based systems:

rpm -q kernel

Distribution kernels frequently backport security fixes without changing the upstream version in an obvious way. Always check the vendor advisory/changelog.


🛡️ Mitigation

The primary mitigation is to upgrade to a kernel containing the security fix.

Debian/Kali:

sudo apt update
sudo apt full-upgrade

Then reboot:

sudo reboot

Verify:

uname -r

For production systems, consult the Linux distribution's official security advisory before applying kernel updates.


🧰 Research Environment

Recommended isolated environment:

Host
 │
 ├── Kali Linux
 │
 └── Vulnerable Linux VM
       │
       ├── Debug kernel
       ├── IPv6 enabled
       ├── AH6/XFRM support
       └── Kernel symbols

Useful debugging tools:

gdb
gef
pwndbg
crash
dmesg
pahole
objdump
readelf

Kernel debugging:

sudo dmesg -w

Inspect kernel symbols:

cat /proc/kallsyms

📂 Repository Structure

CVE-2026-80844-DirtyAH6/
│
├── README.md
│
├── exploit/
│   ├── poc.c
│   └── Makefile
│
├── analysis/
│   ├── vulnerability.md
│   ├── root-cause.md
│   └── patch-analysis.md
│
├── kernel/
│   ├── vulnerable.patch
│   └── fixed.patch
│
├── docs/
│   └── research-notes.md
│
├── screenshots/
│
└── LICENSE

🧪 Proof of Concept

PoC material should only be executed inside an isolated laboratory environment.

The research implementation focuses on demonstrating the malformed IPv6 Routing Header condition and observing the resulting kernel behavior.

Expected research workflow:

下载工具