Exploitable in default config (incl. regular-track kernel updates) ------------------------------------------------------------------ | Target | Details | | --- | --- | | AlmaLinux 9.7 Workstation/Azure cloud, 9.8, 10.1 Workstation/Azure cloud, and 10.2 x86-64/x86-64-v2 | - | | Alpine Linux 3.22.4/3.23.4/3.24.1 Cloud and 3.22.5/3.23.5/3.24.1 LTS/virt | - | | Amazon Linux 2023 KVM (6.1/6.12/6.18 kernel tracks) | - | | Arch Linux monthly (linux/linux-lts/linux-zen) | - | | CentOS Stream 9 Cinnamon/GNOME/KDE/MATE/XFCE and 10 GNOME/KDE | - | | Debian 12/13 | - | | Fedora 40 Workstation/Server | Upstream stable 6.8 never received the OVS cap-removal change; stock 6.8.5-301.fc40 rejects the oversized action, while an ordinary update to 6.14.5-100.fc40 is exploitable. | | Fedora 41 Workstation/Server | Upstream stable 6.11 never received the OVS cap-removal change; stock 6.11.4-301.fc41 rejects the oversized action, while an ordinary update to 6.17.10-100.fc41 is exploitable. | | Fedora 42/43/44 Workstation/Server | - | | Gentoo amd64 cloud image and stable gentoo-kernel-bin 6.1/6.6/6.12/6.18 branches | - | | Kali Linux 2026.1 | - | | Linux Mint 22.3 Cinnamon | - | | NixOS 24.11/25.05/25.11/26.05 | - | | openSUSE Tumbleweed GNOME/KDE | - | | Pop!_OS 22.04 Intel/24.04 Generic | - | | Rocky Linux 9/10 KDE/Workstation/Workstation Lite | - | | Ubuntu 22.04 Desktop minimal/full and Server | - | | Ubuntu 24.04 Desktop minimal/full and Server | Direct unshare is blocked by AppArmor userns policy; exploitable via aa-exec -p trinity. | Exploitable after some tweaks ----------------------------- | Target | Details | | --- | --- | | Arch Linux monthly (linux-hardened) | Stock kernel.unprivileged_userns_clone=0 blocks reachability. Setting it to 1 makes exact 7.1.4-hardened1-1-hardened exploitable, though granted this contradicts the whole point of the hardening. | | Linux Mint 21.3 Cinnamon | Upstream stable 5.15 received the change in 5.15.180, but stock 5.15.0-91-generic does not carry that backport and rejects the oversized action. Installing the optional linux-generic-hwe-22.04 and booting into 6.8.0-134-generic makes it exploitable. | | Oracle Linux 8/9/10 KVM | The stock images lack the required Open vSwitch/conntrack module files; exploitable after installing and loading the missing module packages. | | Ubuntu 26.04 Desktop minimal/full, Server, and generic/AWS/Azure/GCP/GKE/Oracle cloud kernel tracks | Blocked by the stock AppArmor unprivileged-user-namespace policy; exploitable after setting kernel.apparmor_restrict_unprivileged_userns=0. | Not exploitable across available tested distro kernels ------------------------------------------------------ | Target | Details | | --- | --- | | Amazon Linux 2 KVM | Unaffected: the upstream 5.10 stable line never received the OVS cap-removal change; tested 5.10.257-254.1015.amzn2 retains the cap. | | Debian 11 | Unaffected: the upstream 5.10 stable line never received the OVS cap-removal change; tested 5.10.0-44 retains the cap. | | openSUSE Leap 16.0 OEM GNOME/KDE and Minimal-VM | Unaffected: upstream stable 6.12 received the change in 6.12.20, but interestingly the tested SUSE 6.12.0-160000.35 does not carry that backport and rejects the oversized action. | | Rocky Linux 8 GenericCloud | Unaffected: the distro 4.18 kernel line never received the OVS cap-removal change; tested stock and updated kernels retain the cap. | | Ubuntu 18.04 Desktop/Server | Unaffected: the upstream 4.15 stable line never received the OVS cap-removal change; tested 4.15.0-213 retains the cap. | | Ubuntu 20.04 Desktop minimal/full and Server | Unaffected: the 5.4 GA line never received the change; although upstream stable 5.15 received it in 5.15.180, tested Ubuntu HWE 5.15.0-139 does not carry that backport. |