Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-68121 — Research repository for CVE-2026-68121, a Linux kernel PPPoE use-after-free in pppoe_sendmsg() enabling local privilege escalation, with PoC, root-cause analysis, and lab setup. | Kitploit
उपकरण/GitHubGitHub/0xblackash/cve-2026-68121
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationReverse EngineeringPapers & ResearchLearning & EducationBinary ExploitationLabs & Practice
GitHub0xblackash/cve-2026-68121

CVE-2026-68121

Research repository for CVE-2026-68121, a Linux kernel PPPoE use-after-free in pppoe_sendmsg() enabling local privilege escalation, with PoC, root-cause analysis, and lab setup.

14311 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

⚡ CVE-2026-68121 - PPPoEject

Gemini_Generated_Image_f5uscnf5uscnf5us (1)

Linux Kernel PPPoE Use-After-Free → Local Privilege Escalation

A Linux kernel memory-corruption vulnerability in the PPPoE transmit path, caused by a stale pointer to an sk_buff header after a device header callback reallocates the skb head.


⚠️ Disclaimer

This repository is intended for authorized security research, kernel vulnerability analysis, CTF environments, and defensive testing only.

Do not execute proof-of-concept code against systems without explicit authorization.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-68121
CodenamePPPoEject
ComponentLinux Kernel
SubsystemPPPoE / Networking
Affected Filedrivers/net/ppp/pppoe.c
Primary Functionpppoe_sendmsg()
Bug ClassUse-After-Free
ImpactKernel memory corruption
Potential ImpactLocal Privilege Escalation
CVSS v3.17.8 — High
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
StatusPatched

The CVE record identifies the vulnerability as a stale PPPoE header pointer that can become invalid when dev_hard_header() reallocates the skb head.


🧬 Vulnerability Description

The vulnerability exists in:

drivers/net/ppp/pppoe.c

within:

pppoe_sendmsg()

The vulnerable sequence is conceptually:

pppoe_sendmsg()
      │
      ▼
Save PPPoE header pointer
      │
      ▼
dev_hard_header()
      │
      ▼
skb head may be reallocated
      │
      ▼
Old pointer becomes stale
      │
      ▼
PPPoE writes through stale pointer
      │
      ▼
Use-After-Free
      │
      ▼
Kernel memory corruption

Linux networking code allows device header callbacks to reallocate the sk_buff head. A pointer into the old head therefore cannot safely be reused after dev_hard_header() returns.


🔬 Root Cause

The core issue is a lifetime violation.

pppoe_sendmsg() obtains a pointer to the PPPoE header before invoking:

dev_hard_header()

However, that callback can cause the skb head to move.

Conceptually:

Before callback:

skb
┌──────────────────────────────┐
│ Ethernet │ PPPoE │ Payload   │
└──────────┴───────┴───────────┘
           ▲
           │
       stale pointer


After skb expansion:

old skb head ──X──► freed

new skb head
┌────────────────────────────────────┐
│ Ethernet │ PPPoE │ Payload         │
└──────────┴───────┴─────────────────┘
           ▲
           │
      valid location

The old pointer still references the freed allocation.

When PPPoE subsequently writes the header through that pointer, the kernel performs a use-after-free write.


🧠 Trigger Condition

The documented trigger involves a race around copy_from_user() and changes to a team device's header operations.

One described sequence is:

PPPoE sendmsg()
      │
      ▼
copy_from_user() blocks
      │
      │
      ├───────────────┐
      │               │
      ▼               ▼
Team device changes   First non-Ethernet
header operations     port is added
                      │
                      ▼
               Delegated GRE callback
                      │
                      ▼
               skb head expansion
      │               │
      └───────────────┘
              │
              ▼
       stale PPPoE pointer
              │
              ▼
       use-after-free write

The CVE record notes that this can occur when the first non-Ethernet port is added to an empty team device and the delegated GRE header callback expands the skb head.


💥 Security Impact

The vulnerability can result in:

  • Kernel heap use-after-free
  • Kernel memory corruption
  • Kernel crash / denial of service
  • Potential kernel memory disclosure
  • Potential arbitrary kernel memory modification
  • Potential kernel code execution
  • Local privilege escalation

The CVE's published CVSS vector is:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

with a base score of 7.8 High.


🔎 Technical Attack Surface

The relevant components are:

PF_PPPOX / PPPoE socket
          │
          ▼
    pppoe_sendmsg()
          │
          ▼
     sk_buff (skb)
          │
          ▼
  dev_hard_header()
          │
          ▼
 Network device header callback
          │
          ▼
 Potential skb head expansion
          │
          ▼
 PPPoE stale header pointer
          │
          ▼
     UAF write

The vulnerable code is therefore not simply a generic PPPoE packet parser; the critical condition is the interaction between PPPoE socket transmission and dynamic skb head reallocation.


🩹 Upstream Fix

The upstream fix is titled:

pppoe: reload header pointer after dev_hard_header()

The fix reloads the PPPoE header through the skb's network-header offset after device header creation.

The important property is:

Before:

header pointer
      │
      ▼
dev_hard_header()
      │
      ▼
skb moves
      │
      ▼
pointer = stale ❌


After:

dev_hard_header()
      │
      ▼
skb may move
      │
      ▼
reload header using skb offset
      │
      ▼
pointer = valid ✅

pskb_expand_head() updates the relevant skb offset when the skb head is relocated, making the offset-based lookup safe after reallocation.


📊 Vulnerable vs Patched

Security PropertyVulnerablePatched
Header pointer saved before callback✅—
skb head can move✅✅
Pointer refreshed after callback❌✅
Stale pointer dereferencePossiblePrevented
Use-after-free writePossibleMitigated
Kernel memory corruptionPossibleMitigated

🧪 Research Environment

A controlled laboratory can be structured as:

टूल डाउनलोड करें