Junglewise Threat Intelligence

CVE-2026-64119: Linux Kernel infinite loop in l2tp_session_unhash

CVE-2026-64119 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) component allows a local user to cause a permanent system hang or denial of service. By triggering specific networking commands, an attacker can force a processor into an infinite loop that cannot be interrupted, effectively freezing the host. This can lead to a complete loss of availability for the affected server.

Technical details

A race condition exists in net/l2tp/l2tp_core.c due to the improper use of list_del_init() instead of list_del_rcu() in l2tp_session_unhash(). While l2tp_session_get_by_ifname() walks the session list using RCU-safe macros, the unhash function uses a non-RCU delete variant that leaves the entry's next/prev pointers self-pointing. A concurrent reader can become trapped in an infinite loop while traversing the list under rcu_read_lock_bh(), disabling preemption and stalling RCU grace periods. This attack is reachable from an unprivileged user namespace (e.g., via unshare -Urn) provided the l2tp_core module is loaded. The issue has been resolved by switching to list_del_rcu().

Affected products

  • Linux Linux Kernel 6.11+

Timeline

  • 2026-05-18: disclosed: Initial patch submission by Michael Bommarito
  • 2026-07-19: advisory: CVE-2026-64119 published

References

Related threats