Executive brief
A vulnerability in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) component allows a local user to cause a permanent system hang or denial of service. By triggering specific networking commands, an attacker can force a processor into an infinite loop that cannot be interrupted, effectively freezing the host. This can lead to a complete loss of availability for the affected server.
Technical details
A race condition exists in net/l2tp/l2tp_core.c due to the improper use of list_del_init() instead of list_del_rcu() in l2tp_session_unhash(). While l2tp_session_get_by_ifname() walks the session list using RCU-safe macros, the unhash function uses a non-RCU delete variant that leaves the entry's next/prev pointers self-pointing. A concurrent reader can become trapped in an infinite loop while traversing the list under rcu_read_lock_bh(), disabling preemption and stalling RCU grace periods. This attack is reachable from an unprivileged user namespace (e.g., via unshare -Urn) provided the l2tp_core module is loaded. The issue has been resolved by switching to list_del_rcu().
Affected products
- Linux Linux Kernel 6.11+
Timeline
- 2026-05-18: disclosed: Initial patch submission by Michael Bommarito
- 2026-07-19: advisory: CVE-2026-64119 published