CVE-2026-68398 PoC:Ubuntu PPPoL2TP 内核释放后使用本地权限提升
github.com | 漏洞 | 高危 | CVE-2026-68398 | #public-poc | #kernel-security | #privilege-escalation | #use-after-free | #linux-kernel | #ubuntu | #pppol2tp | #cve | #poc | #cve-2026-68398
摘要
CVE-2026-68398 公开 PoC:Linux 内核 PPPoL2TP 接收路径存在释放后使用(UAF)竞态,非特权用户可在 Ubuntu 22.04 的 5.15.0-187 内核上提权至初始命名空间 root;利用在 KASLR、SMEP、SMAP 与 AppArmor 均开启的情况下验证成功。
为什么值得关注
该 PoC 将内核 UAF 转化为普通用户到 root 的本地提权,适合用于授权的 Linux 内核安全研究和补丁验证。利用会竞争内核堆并可能导致系统崩溃或损坏,只应在隔离、可回滚的实验虚拟机中运行,并及时安装包含修复的内核更新。
- 厂商
- Linux
- 产品
- Linux kernel PPPoL2TP
- 受影响版本
- Linux kernel vulnerable lineage begins at 4.15; validated target Ubuntu 22.04.5 LTS linux-image-5.15.0-187-generic / 5.15.0-187.197; mainline fixes include 6.6.148, 6.12.101, 6.18.42, 7.1.6 and 7.2-rc4; vendor backports may differ
- CVSS
- 7.8
- 发布时间
- 收录时间
Skip to content