PT-2026-69521 · Linux · Linux Kernel

CVE-2026-68121

·

Published

2026-07-22

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the pppoe sendmsg() function where a pointer to the PPPoE header is saved before calling dev hard header(). Because device header callbacks can reallocate the skb head, any previously saved pointers into it may become invalid. This occurs when a send operation is blocked in copy from user() while a non-Ethernet port is added to an empty team device, causing the GRE header callback to expand the skb head. Consequently, PPPoE writes six bytes using a stale pointer into the freed head memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:71329
ALSA-2026:71330
BDU:2026-14929
CVE-2026-68121
OESA-2026-3706
OPENSUSE-SU-2026:21910-1
SUSE-SU-2026:23477-1
SUSE-SU-2026:23481-1
SUSE-SU-2026:23528-1
SUSE-SU-2026:23529-1
SUSE-SU-2026:4120-1
SUSE-SU-2026:4190-1
SUSE-SU-2026:4254-1
SUSE-SU-2026:4279-1
SUSE-SU-2026:4282-1
SUSE-SU-2026:4284-1
SUSE-SU-2026:4347-1

Affected Products

Linux Kernel