CVE-2026-53075 is an incorrect authorization vulnerability in the Linux kernel PPP subsystem. Opening the PPP character device is authorized against the file credentials' user namespace, whereas unattached administrative ioctls operate on the caller's current network namespace. A local unprivileged user can create a new user namespace with CLONE_NEWUSER, obtain CAP_NET_ADMIN within it, and invoke PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against an inherited network namespace without the required privilege in that namespace's owning user namespace. The mismatch permits unauthorized PPP administrative operations across a namespace privilege boundary.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel PPP authorization flaw allows a local unprivileged user with CAP_NET_ADMIN in a newly created user namespace to perform administrative PPP operations against an inherited network namespace where they lack that capability. The fix checks privileges in the user namespace owning the target network namespace. The reference rates the vulnerability High, with a CVSS v3 base score of 8.8, and recommends updating the affected Google kernel packages to version 18867.381.201 or later.
A local authorization flaw in Linux kernel PPP handling allows an unprivileged user with CAP_NET_ADMIN in a newly created user namespace to perform administrative PPP operations against an inherited network namespace where they lack that privilege. The fix checks CAP_NET_ADMIN in the user namespace owning the target network namespace. The advisory rates the vulnerability High, with a CVSS v3 base score of 8.8, and reports available exploits.
A vulnerability addressed in Huawei EulerOS UVP 2.10.1 kernel-related packages.
A vulnerability addressed by Alma Linux advisory RHSA-2026:68531; no technical details are supplied.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.