KernelScan.io

HIGH Public exploit Introduced in 2.6.12

PPPoEject

CVE-2026-68121

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.

02

Engine v0.6.0

Risk summary

A local unprivileged user who can create a PPPoE socket and configure a team network device — both possible inside a user namespace — can trigger a use-after-free write in the kernel via a race condition during packet sending. The six-byte write through a stale pointer into freed memory can corrupt kernel heap objects, leading to privilege escalation, information disclosure, or a system crash. The race requires precise timing but is controllable with techniques such as userfaultfd.

Affecteddrivers/net/ppp/pppoe.c (PPPoE protocol driver)

Vulnerability analysis

The PPPoE send path saves a pointer to the packet header before calling the device's header-building callback. That callback is permitted to reallocate the underlying socket buffer, which invalidates the saved pointer. When a concurrent configuration change on a team network device triggers such a reallocation, the PPPoE code writes through the stale pointer into freed memory. The fix reloads the header pointer from the socket buffer's metadata after the device header callback returns, so any reallocation is accounted for. The bug is reachable from a local process that can create a PPPoE socket and configure a team device — operations that require network administration privileges obtainable inside a user namespace, making it exploitable by an unprivileged local user on configurations where user namespaces are enabled.

Exploit availability

KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.

03

BranchIntroducedFixed inPatch commit
5.152.6.125.15.2166eed5ae7887a
6.12.6.126.1.183ba3409369c54
6.122.6.126.12.1017e9fbd7f96bc
6.182.6.126.18.426866abf59976
7.12.6.127.1.6bed4caecd723
5.102.6.125.10.2657a56e7c9b08e
6.62.6.126.6.148e6493a4d1ee1
mainline2.6.127.2e9c238f6fe42