CVE-2026-68121
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
19/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
pppoe: reload header pointer after dev_hard_header()<br />
<br />
pppoe_sendmsg() saves a pointer to the PPPoE header before calling<br />
dev_hard_header(). Device header callbacks are allowed to reallocate the<br />
skb head, invalidating pointers into it.<br />
<br />
This can happen when a send is blocked in copy_from_user() while the first<br />
non-Ethernet port is added to an empty team device. The team&#39;s delegated<br />
GRE header callback then expands the skb head. PPPoE subsequently writes<br />
six bytes through the stale pointer into the freed head.<br />
<br />
Reload the PPPoE header through the skb&#39;s network-header offset after<br />
device header creation. pskb_expand_head() updates that offset when it<br />
relocates the head.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/6866abf59976d273164a6624234d96a967280223
- https://git.kernel.org/stable/c/6eed5ae7887a93160803d2b81ff88e75eefd4a4c
- https://git.kernel.org/stable/c/7a56e7c9b08e08fd55a1bcada24cf4fe3782b722
- https://git.kernel.org/stable/c/7e9fbd7f96bcde63a7c798fe16b38cedee7a1501
- https://git.kernel.org/stable/c/ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a
- https://git.kernel.org/stable/c/bed4caecd723693f750e13adbb2c42ca1249a3fd
- https://git.kernel.org/stable/c/e6493a4d1ee17595766165fa446d45b7e0c318d0
- https://git.kernel.org/stable/c/e9c238f6fe42fb1b4dba3a578277de32cb487937


