HIGH Introduced in 2.6.30
ppp UnattachedIoctl Bypass
CVE-2026-53075
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls /dev/ppp open is currently authorized against file->f_cred->user_ns, while unattached administrative ioctls operate on current->nsproxy->net_ns. As a result, a local unprivileged user can create a new user namespace with CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace, and still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against an inherited network namespace. Require CAP_NET_ADMIN in the user namespace that owns the target network namespace before handling unattached PPP administrative ioctls. This preserves normal pppd operation in the network namespace it is actually privileged in, while rejecting the userns-only inherited-netns case.
02KernelScan AI Analysis
Risk summary
An unprivileged local user can create a user namespace to gain CAP_NET_ADMIN scoped only to that namespace, then issue privileged PPP administrative ioctls (PPPIOCNEWUNIT, PPPIOCATTACH, PPPIOCATTCHAN) against an inherited network namespace. This allows unauthorized manipulation of PPP units and channels in a network namespace the attacker does not legitimately control. The impact is limited to integrity and availability: the attacker can tamper with network configuration and disrupt PPP connectivity within the affected namespace, but no direct confidentiality loss occurs.
Vulnerability analysis
The vulnerability is an improper authorization check in ppp_unattached_ioctl() in drivers/net/ppp/ppp_generic.c. The /dev/ppp file open authorization checks credentials against file->f_cred->user_ns, but the unattached ioctl handler operates on current->nsproxy->net_ns (the current network namespace). An unprivileged user can call CLONE_NEWUSER to create a new user namespace in which they hold CAP_NET_ADMIN, then open /dev/ppp (authorized against their new user_ns), and issue privileged PPP ioctls that operate on the inherited parent network namespace — for which they do not legitimately hold CAP_NET_ADMIN. The fix adds a single ns_capable(net->user_ns, CAP_NET_ADMIN) check at the top of ppp_unattached_ioctl(), requiring that the caller hold CAP_NET_ADMIN in the user namespace that owns the target network namespace, not merely in any user namespace. This closes the gap between the open-time credential check and the ioctl-time namespace context. The attack is purely local and requires only the ability to create user namespaces (available by default on most Linux distributions).
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.15 | 2.6.30 | 5.15.209 | 5080e188c914 |
| 6.1 | 2.6.30 | 6.1.175 | 67e901e28d17 |
| 6.12 | 2.6.30 | 6.12.91 | 3b2c2157dc2a |
| 7.0 | 2.6.30 | 7.0.10 | 1a8a51ce8507 |
| mainline | 2.6.30 | 7.1 | 2bb6379416fd |
| 6.18 | 2.6.30 | 6.18.33 | 5013be175c7f |
| 6.6 | 2.6.30 | 6.6.141 | 954745d0223e |
| 5.10 | 2.6.30 | 5.10.258 | c9edd90c57ae |