CVE-2026-53003
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
14/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
pppoe: drop PFC frames<br />
<br />
RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT<br />
RECOMMENDED for PPPoE. In practice, pppd does not support negotiating<br />
PFC for PPPoE sessions, and the current PPPoE driver assumes an<br />
uncompressed (2-byte) protocol field. However, the generic PPP layer<br />
function ppp_input() is not aware of the negotiation result, and still<br />
accepts PFC frames.<br />
<br />
If a peer with a broken implementation or an attacker sends a frame with<br />
a compressed (1-byte) protocol field, the subsequent PPP payload is<br />
shifted by one byte. This causes the network header to be 4-byte<br />
misaligned, which may trigger unaligned access exceptions on some<br />
architectures.<br />
<br />
To reduce the attack surface, drop PPPoE PFC frames. Introduce<br />
ppp_skb_is_compressed_proto() helper function to be used in both<br />
ppp_generic.c and pppoe.c to avoid open-coding.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.0 (including) | 5.10.258 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.209 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.141 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0cab5d077dd1efd2bd1a47271acc35894f945b4f
- https://git.kernel.org/stable/c/2b5c3c040d020e3ab3b9a8887031202d96843b1e
- https://git.kernel.org/stable/c/49e41b60ccd1bdbe9e218420f716dd5f9a2f9c71
- https://git.kernel.org/stable/c/8a5e840babc5c0fbd10c73728a13192347771ec6
- https://git.kernel.org/stable/c/ba758fdf1399f310b30098b6faa3fd043de47dd2
- https://git.kernel.org/stable/c/cb3beef35ab5e0c1afca9fd7648c6ae499786377
- https://git.kernel.org/stable/c/cc1ff87bce1ccd38410ab10960f576dcd17db679
- https://git.kernel.org/stable/c/fcca1df05322bb04e344dd1178b54b76a08eb7c3



