AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68121

HIGH · CVSS 7.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel affects the PPPoE implementation, where a stale pointer to the PPPoE header can lead to writing data into a freed memory area after device header callbacks reallocate the socket buffer (skb) head. This can result in potential memory corruption and unpredictable behavior, which may be exploited by attackers to execute arbitrary code or cause denial of service. Organizations using Linux systems with PPPoE should prioritize addressing this vulnerability to mitigate risks associated with memory management issues.

CVE
CVE-2026-68121
Severity
HIGH
CVSS
7.8
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.