Junglewise Threat Intelligence

CVE-2026-53075: Linux Kernel permission bypass in PPP administrative ioctls

CVE-2026-53075 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Point-to-Point Protocol (PPP) driver could allow a local user to perform unauthorized network administrative actions. By exploiting a flaw in how the system checks permissions across different user environments (namespaces), an unprivileged user could create or modify network interfaces they should not have access to. This could lead to unauthorized network configuration changes or disruption of network services on the affected system.

Technical details

A vulnerability exists in the Linux kernel's ppp_generic driver where unattached administrative ioctls (PPPIOCNEWUNIT, PPPIOCATTACH, PPPIOCATTCHAN) are incorrectly authorized. While opening /dev/ppp is checked against the file opener's user namespace, the subsequent ioctls operate on the current network namespace. A local attacker can use CLONE_NEWUSER to create a new user namespace where they have CAP_NET_ADMIN, then use that privilege to issue ioctls against an inherited network namespace from the parent environment. The fix implements a check requiring CAP_NET_ADMIN within the user namespace that owns the target network namespace.

Affected products

  • Linux Linux 2.6.30 to 6.14

Timeline

  • 2026-04-09: disclosed: Initial patch submitted by Taegu Ha
  • 2026-06-24: advisory: CVE-2026-53075 published

References