HOMEVULNERABILITIESCVE-2026-53075
HIGH

CVE-2026-53075

Published: June 24, 2026· Updated: Jun 28, 2026

8.8
CVSS v3.1
EPSS:0.26%probability of exploitation in 30 daysPercentile:17.0th

Official Description

In the Linux kernel, the following vulnerability has been resolved:

ppp: require CAP_NET_ADMIN in target netns for unattached ioctls

/dev/ppp open is currently authorized against file->f_cred->user_ns,

while unattached administrative ioctls operate on current->nsproxy->net_ns.

As a result, a local unprivileged user can create a new user namespace

with CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace,

and still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against

an inherited network namespace.

Require CAP_NET_ADMIN in the user namespace that owns the target network

namespace before handling unattached PPP administrative ioctls.

This preserves normal pppd operation in the network namespace it is

actually privileged in, while rejecting the userns-only inherited-netns

case.

NVD Source

Technical Analysis

CVE-2026-53075 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 8.8.

The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityLow
Privileges Req.Low
User InteractionNone
ScopeChanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Vendors & Products

Mentioned vendors (from description):
Linux
CPE data not yet available in NVD for this CVE.

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

All References (8)

Quick Facts

CVE IDCVE-2026-53075
CVSS Score8.8 / 10
SeverityHIGH
CISA KEVNo
EPSS (30d)0.26%
PublishedJun 24, 2026

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-53075 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWATCH.COM. CVE data is provided under the NVD usage policy.