
🔴 Linux kernel'in PPPoL2TP bileşenindeki Use-After-Free (UAF) race condition zafiyeti (CVE-2026-68398) için çalışan bir LPE PoC/exploit yayınlandı. Exploit, ayrıcalıksız bir yerel kullanıcıdan root (UID 0) elde edebiliyor. Araştırmacı, exploit'i Ubuntu 22.04.5 LTS / kernel 5.15.0-187-generic üzerinde QEMU/KVM ortamında doğrulamış. KASLR, SMEP, SMAP ve AppArmor aktif durumda. https://github.com/aramosf/cve-2026-68398
Post summary
A Proof‑of‑Concept exploit for CVE-2026-68398, targeting a Use-After-Free in the Linux kernel's PPPoL2TP component, was published on GitHub and demonstrates local privilege escalation to root.


