Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-68121 — Research repository for CVE-2026-68121, a Linux kernel PPPoE use-after-free in pppoe_sendmsg() enabling local privilege escalation, with PoC, root-cause analysis, and lab setup. | Kitploit
도구/GitHubGitHub/0xblackash/cve-2026-68121
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationReverse EngineeringPapers & ResearchLearning & EducationBinary ExploitationLabs & Practice
GitHub0xblackash/cve-2026-68121

CVE-2026-68121

Research repository for CVE-2026-68121, a Linux kernel PPPoE use-after-free in pppoe_sendmsg() enabling local privilege escalation, with PoC, root-cause analysis, and lab setup.

14311일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

⚡ CVE-2026-68121 - PPPoEject

Gemini_Generated_Image_f5uscnf5uscnf5us (1)

Linux Kernel PPPoE Use-After-Free → Local Privilege Escalation

A Linux kernel memory-corruption vulnerability in the PPPoE transmit path, caused by a stale pointer to an sk_buff header after a device header callback reallocates the skb head.


⚠️ Disclaimer

This repository is intended for authorized security research, kernel vulnerability analysis, CTF environments, and defensive testing only.

Do not execute proof-of-concept code against systems without explicit authorization.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-68121
CodenamePPPoEject
ComponentLinux Kernel
SubsystemPPPoE / Networking
Affected Filedrivers/net/ppp/pppoe.c
Primary Functionpppoe_sendmsg()
Bug ClassUse-After-Free
ImpactKernel memory corruption
Potential ImpactLocal Privilege Escalation
CVSS v3.17.8 — High
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
StatusPatched

The CVE record identifies the vulnerability as a stale PPPoE header pointer that can become invalid when dev_hard_header() reallocates the skb head.


🧬 Vulnerability Description

The vulnerability exists in:

drivers/net/ppp/pppoe.c

within:

pppoe_sendmsg()

The vulnerable sequence is conceptually:

pppoe_sendmsg()
      │
      ▼
Save PPPoE header pointer
      │
      ▼
dev_hard_header()
      │
      ▼
skb head may be reallocated
      │
      ▼
Old pointer becomes stale
      │
      ▼
PPPoE writes through stale pointer
      │
      ▼
Use-After-Free
      │
      ▼
Kernel memory corruption

Linux networking code allows device header callbacks to reallocate the sk_buff head. A pointer into the old head therefore cannot safely be reused after dev_hard_header() returns.


🔬 Root Cause

The core issue is a lifetime violation.

pppoe_sendmsg() obtains a pointer to the PPPoE header before invoking:

dev_hard_header()

However, that callback can cause the skb head to move.

Conceptually:

Before callback:

skb
┌──────────────────────────────┐
│ Ethernet │ PPPoE │ Payload   │
└──────────┴───────┴───────────┘
           ▲
           │
       stale pointer


After skb expansion:

old skb head ──X──► freed

new skb head
┌────────────────────────────────────┐
│ Ethernet │ PPPoE │ Payload         │
└──────────┴───────┴─────────────────┘
           ▲
           │
      valid location

The old pointer still references the freed allocation.

When PPPoE subsequently writes the header through that pointer, the kernel performs a use-after-free write.


🧠 Trigger Condition

The documented trigger involves a race around copy_from_user() and changes to a team device's header operations.

One described sequence is:

PPPoE sendmsg()
      │
      ▼
copy_from_user() blocks
      │
      │
      ├───────────────┐
      │               │
      ▼               ▼
Team device changes   First non-Ethernet
header operations     port is added
                      │
                      ▼
               Delegated GRE callback
                      │
                      ▼
               skb head expansion
      │               │
      └───────────────┘
              │
              ▼
       stale PPPoE pointer
              │
              ▼
       use-after-free write

The CVE record notes that this can occur when the first non-Ethernet port is added to an empty team device and the delegated GRE header callback expands the skb head.


💥 Security Impact

The vulnerability can result in:

  • Kernel heap use-after-free
  • Kernel memory corruption
  • Kernel crash / denial of service
  • Potential kernel memory disclosure
  • Potential arbitrary kernel memory modification
  • Potential kernel code execution
  • Local privilege escalation

The CVE's published CVSS vector is:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

with a base score of 7.8 High.


🔎 Technical Attack Surface

The relevant components are:

PF_PPPOX / PPPoE socket
          │
          ▼
    pppoe_sendmsg()
          │
          ▼
     sk_buff (skb)
          │
          ▼
  dev_hard_header()
          │
          ▼
 Network device header callback
          │
          ▼
 Potential skb head expansion
          │
          ▼
 PPPoE stale header pointer
          │
          ▼
     UAF write

The vulnerable code is therefore not simply a generic PPPoE packet parser; the critical condition is the interaction between PPPoE socket transmission and dynamic skb head reallocation.


🩹 Upstream Fix

The upstream fix is titled:

pppoe: reload header pointer after dev_hard_header()

The fix reloads the PPPoE header through the skb's network-header offset after device header creation.

The important property is:

Before:

header pointer
      │
      ▼
dev_hard_header()
      │
      ▼
skb moves
      │
      ▼
pointer = stale ❌


After:

dev_hard_header()
      │
      ▼
skb may move
      │
      ▼
reload header using skb offset
      │
      ▼
pointer = valid ✅

pskb_expand_head() updates the relevant skb offset when the skb head is relocated, making the offset-based lookup safe after reallocation.


📊 Vulnerable vs Patched

Security PropertyVulnerablePatched
Header pointer saved before callback✅—
skb head can move✅✅
Pointer refreshed after callback❌✅
Stale pointer dereferencePossiblePrevented
Use-after-free writePossibleMitigated
Kernel memory corruptionPossibleMitigated

🧪 Research Environment

A controlled laboratory can be structured as:

도구 다운로드