HIGH Public exploit Introduced in 2.6.12
PPPoEject
CVE-2026-68121
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.
02KernelScan AI Analysis
Risk summary
A local unprivileged user who can create a PPPoE socket and configure a team network device — both possible inside a user namespace — can trigger a use-after-free write in the kernel via a race condition during packet sending. The six-byte write through a stale pointer into freed memory can corrupt kernel heap objects, leading to privilege escalation, information disclosure, or a system crash. The race requires precise timing but is controllable with techniques such as userfaultfd.
Vulnerability analysis
The PPPoE send path saves a pointer to the packet header before calling the device's header-building callback. That callback is permitted to reallocate the underlying socket buffer, which invalidates the saved pointer. When a concurrent configuration change on a team network device triggers such a reallocation, the PPPoE code writes through the stale pointer into freed memory. The fix reloads the header pointer from the socket buffer's metadata after the device header callback returns, so any reallocation is accounted for. The bug is reachable from a local process that can create a PPPoE socket and configure a team device — operations that require network administration privileges obtainable inside a user namespace, making it exploitable by an unprivileged local user on configurations where user namespaces are enabled.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.15 | 2.6.12 | 5.15.216 | 6eed5ae7887a |
| 6.1 | 2.6.12 | 6.1.183 | ba3409369c54 |
| 6.12 | 2.6.12 | 6.12.101 | 7e9fbd7f96bc |
| 6.18 | 2.6.12 | 6.18.42 | 6866abf59976 |
| 7.1 | 2.6.12 | 7.1.6 | bed4caecd723 |
| 5.10 | 2.6.12 | 5.10.265 | 7a56e7c9b08e |
| 6.6 | 2.6.12 | 6.6.148 | e6493a4d1ee1 |
| mainline | 2.6.12 | 7.2 | e9c238f6fe42 |