Executive brief
A vulnerability was identified in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) implementation, which is used to support virtual private networks (VPNs). A technical error in how the system tracks active connections could allow a local attacker to cause a system crash or potentially execute unauthorized actions by accessing memory that has already been freed. This issue primarily affects specialized real-time Linux configurations (PREEMPT_RT) and could impact system stability and availability.
Technical details
A use-after-free (UAF) vulnerability exists in net/l2tp/l2tp_core.c within the l2tp_session_get_by_ifname() function. The root cause is a race condition where a reader can be preempted between a string comparison and a reference count increment (refcount_inc). If the session's reference count drops to zero on another CPU during this window, the getter may return a pointer to a session that is subsequently freed by kfree_rcu() once the RCU grace period expires. This is particularly exploitable on PREEMPT_RT kernels where local_bh_disable() allows preemption. The fix replaces refcount_inc() with refcount_inc_not_zero() to ensure references are only taken on valid objects.
Affected products
- Linux Linux Kernel abe7a1a7d0b6 to ee80455feffb
Timeline
- 2026-05-22: other: Patch authored
- 2026-07-19: disclosed: CVE published