CVE-2026-53075
published 2026-06-24CVE-2026-53075: In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls /dev/ppp open is currently…
PriorityP348high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
/dev/ppp open is currently authorized against file->f_cred->user_ns,
while unattached administrative ioctls operate on current->nsproxy->net_ns.
As a result, a local unprivileged user can create a new user namespace
with CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace,
and still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against
an inherited network namespace.
Require CAP_NET_ADMIN in the user namespace that owns the target network
namespace before handling unattached PPP administrative ioctls.
This preserves normal pppd operation in the network namespace it is
actually privileged in, while rejecting the userns-only inherited-netns
case.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < c9edd90c57ae23692fff6b049fdfa4572a9fd532 | c9edd90c57ae23692fff6b049fdfa4572a9fd532 |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < 5080e188c914110034bbc569d5cfa2f06204681d | 5080e188c914110034bbc569d5cfa2f06204681d |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < 67e901e28d177ac9a9bed76d69ce3471e704a89e | 67e901e28d177ac9a9bed76d69ce3471e704a89e |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < 954745d0223e7caec917c0b2d1a889ff56fa6e54 | 954745d0223e7caec917c0b2d1a889ff56fa6e54 |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < 3b2c2157dc2afc5c17cd7238afefca92f1ef330e | 3b2c2157dc2afc5c17cd7238afefca92f1ef330e |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < 5013be175c7ffd8b39efbc3c9c4db5b10b85fea8 | 5013be175c7ffd8b39efbc3c9c4db5b10b85fea8 |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < 1a8a51ce85075a56a743b6f142606dd2696a391c | 1a8a51ce85075a56a743b6f142606dd2696a391c |
| linux | linux | >= 273ec51dd7ceaa76e038875d85061ec856d8905e < 2bb6379416fd19f44c3423a00bfd8626259f6067 | 2bb6379416fd19f44c3423a00bfd8626259f6067 |
| linux | linux_kernel | — | — |
| ubuntu | linux | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-gcp-6.8 | — | — |
| ubuntu | linux-gke | — | — |
| ubuntu | linux-gkeop | — | — |
| ubuntu | linux-hwe-7.0 | — | — |
| ubuntu | linux-oem-7.0 | — | — |
| ubuntu | linux-realtime | — | — |
| ubuntu | linux-realtime-6.8 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.9 ppp f_cred improper authorization
vuldb·2026-06-24
CVE-2026-53075 [CRITICAL] Linux Kernel up to 7.0.9 ppp f_cred improper authorization
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.0.9. The impacted element is an unknown function of the component ppp. Performing a manipulation of the argument f_cred results in improper authorization.
This vulnerability is cataloged as CVE-2026-53075. The attack must be initiated from a local position. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls /dev/ppp open is currently authorized against file->f_cred->user_
ghsa_unreviewed·2026-06-24
CVE-2026-53075 In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls /dev/ppp open is currently authorized against file->f_cred->user_
In the Linux kernel, the following vulnerability has been resolved:
ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
/dev/ppp open is currently authorized against file->f_cred->user_ns,
while unattached administrative ioctls operate on current->nsproxy->net_ns.
As a result, a local unprivileged user can create a new user namespace
with CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace,
and still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against
an inherited network namespace.
Require CAP_NET_ADMIN in the user namespace that owns the target network
namespace before handling unattached PPP administrative ioctls.
This preserves normal pppd operation in the network namespace it is
actually privileged in, while rejecting the userns-only inherited-n
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 7.0
CVE-2026-46108 [HIGH] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- PSP security protocol;
- ARM64 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Intel NPU Driver;
- DRBD D
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TC
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacke
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 7.0
CVE-2026-46113 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- PSP security protocol;
- ARM64 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Intel NPU Driver;
- DRBD Distrib
Red Hat
kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
vendor_redhat·2026-06-24·CVSS 7.0
CVE-2026-53075 [MEDIUM] CWE-266 kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
A flaw was found in the Linux kernel's Point-to-Point Protocol (PPP) subsystem. A local unprivileged user can exploit this vulnerability by creating a new user namespace and bypassing authorization checks for unattached administrative input/output controls (ioctls). This allows the user to perform unauthorized administrative operations on an inherited network namespace, potentially leading to privilege escalation.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kerne
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1a8a51ce85075a56a743b6f142606dd2696a391chttps://git.kernel.org/stable/c/2bb6379416fd19f44c3423a00bfd8626259f6067https://git.kernel.org/stable/c/3b2c2157dc2afc5c17cd7238afefca92f1ef330ehttps://git.kernel.org/stable/c/5013be175c7ffd8b39efbc3c9c4db5b10b85fea8https://git.kernel.org/stable/c/5080e188c914110034bbc569d5cfa2f06204681dhttps://git.kernel.org/stable/c/67e901e28d177ac9a9bed76d69ce3471e704a89ehttps://git.kernel.org/stable/c/954745d0223e7caec917c0b2d1a889ff56fa6e54https://git.kernel.org/stable/c/c9edd90c57ae23692fff6b049fdfa4572a9fd532
2026-06-24
Published