Executive brief
NetworkManager-l2tp is a VPN connection handler used to establish Layer 2 Tunneling Protocol (L2TP) connections on Linux systems. Local users with VPN configuration permissions can inject arbitrary commands into the underlying PPP daemon (pppd) by supplying specially crafted mru or mtu values, allowing them to load malicious code and gain root-level access to the system.
Technical details
The vulnerability is an improper input validation flaw in how numeric VPN properties (mru/mtu) are handled. The application validates that a string begins with a valid integer using strtol() but fails to check for trailing content; it then writes the unvalidated original string verbatim into the pppd configuration file via write_config_option(). An attacker can inject additional pppd directives—specifically the plugin directive—by providing values like "1400 plugin /path/to/malicious.so". Since pppd runs with root privileges, this allows arbitrary code execution as root. The attack requires local access and permission to create NetworkManager VPN connections, but no user interaction. A patch is available in version 1.52.6, which enforces complete numeric parsing and serializes only canonical integer values.
Affected products
- NetworkManager-l2tp NetworkManager-l2tp through 1.52.4, fixed in 1.52.6
Timeline
- 2026-09-17: disclosed: Published via GitHub Security Advisory and NVD
- 2026-09-08: patched: Patch commit 64879ce0ad866f7c9a45babe4d95731a916ea00f available; version 1.52.6 contains fix