CVE-2026-53075
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
21/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ppp: require CAP_NET_ADMIN in target netns for unattached ioctls<br />
<br />
/dev/ppp open is currently authorized against file->f_cred->user_ns,<br />
while unattached administrative ioctls operate on current->nsproxy->net_ns.<br />
<br />
As a result, a local unprivileged user can create a new user namespace<br />
with CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace,<br />
and still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against<br />
an inherited network namespace.<br />
<br />
Require CAP_NET_ADMIN in the user namespace that owns the target network<br />
namespace before handling unattached PPP administrative ioctls.<br />
<br />
This preserves normal pppd operation in the network namespace it is<br />
actually privileged in, while rejecting the userns-only inherited-netns<br />
case.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.30 (including) | 5.10.258 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.209 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.141 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1a8a51ce85075a56a743b6f142606dd2696a391c
- https://git.kernel.org/stable/c/2bb6379416fd19f44c3423a00bfd8626259f6067
- https://git.kernel.org/stable/c/3b2c2157dc2afc5c17cd7238afefca92f1ef330e
- https://git.kernel.org/stable/c/5013be175c7ffd8b39efbc3c9c4db5b10b85fea8
- https://git.kernel.org/stable/c/5080e188c914110034bbc569d5cfa2f06204681d
- https://git.kernel.org/stable/c/67e901e28d177ac9a9bed76d69ce3471e704a89e
- https://git.kernel.org/stable/c/954745d0223e7caec917c0b2d1a889ff56fa6e54
- https://git.kernel.org/stable/c/c9edd90c57ae23692fff6b049fdfa4572a9fd532



