CVE-2026-53003

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
14/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> pppoe: drop PFC frames<br /> <br /> RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT<br /> RECOMMENDED for PPPoE. In practice, pppd does not support negotiating<br /> PFC for PPPoE sessions, and the current PPPoE driver assumes an<br /> uncompressed (2-byte) protocol field. However, the generic PPP layer<br /> function ppp_input() is not aware of the negotiation result, and still<br /> accepts PFC frames.<br /> <br /> If a peer with a broken implementation or an attacker sends a frame with<br /> a compressed (1-byte) protocol field, the subsequent PPP payload is<br /> shifted by one byte. This causes the network header to be 4-byte<br /> misaligned, which may trigger unaligned access exceptions on some<br /> architectures.<br /> <br /> To reduce the attack surface, drop PPPoE PFC frames. Introduce<br /> ppp_skb_is_compressed_proto() helper function to be used in both<br /> ppp_generic.c and pppoe.c to avoid open-coding.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.0 (including) 5.10.258 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.209 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.175 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.141 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.91 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)