Junglewise Threat Intelligence

CVE-2026-63918: Linux Kernel use-after-free in l2tp_session_get_by_ifname

CVE-2026-63918 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) implementation, which is used to support virtual private networks (VPNs). A technical error in how the system tracks active connections could allow a local attacker to cause a system crash or potentially execute unauthorized actions by accessing memory that has already been freed. This issue primarily affects specialized real-time Linux configurations (PREEMPT_RT) and could impact system stability and availability.

Technical details

A use-after-free (UAF) vulnerability exists in net/l2tp/l2tp_core.c within the l2tp_session_get_by_ifname() function. The root cause is a race condition where a reader can be preempted between a string comparison and a reference count increment (refcount_inc). If the session's reference count drops to zero on another CPU during this window, the getter may return a pointer to a session that is subsequently freed by kfree_rcu() once the RCU grace period expires. This is particularly exploitable on PREEMPT_RT kernels where local_bh_disable() allows preemption. The fix replaces refcount_inc() with refcount_inc_not_zero() to ensure references are only taken on valid objects.

Affected products

  • Linux Linux Kernel abe7a1a7d0b6 to ee80455feffb

Timeline

  • 2026-05-22: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats