1.
github.com | vulnerability | High | | original ↗ | #public-poc | #kernel-security | #privilege-escalation | #use-after-free
Public PoC for CVE-2026-68398: a use-after-free race in Linux's PPPoL2TP receive path. On Ubuntu 22.04 (5.15.0-187) it takes an unprivileged user to root with KASLR, SMEP, SMAP and AppArmor enabled.
Why it matters: The PoC turns a kernel UAF into local privilege escalation from an ordinary user to root, making it relevant for authorized Linux kernel research and patch validation. The race can panic or corrupt a system, so it should only run in an isolated, recoverable lab VM and affected kernels should be updated.
Skip to content