In the Linux kernel, the following vulnerability has been resolved: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path: l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv() -> ppp_input(&po->chan) It runs under rcu_read_lock() holding only an l2tp_session reference and takes NO reference on the internal PPP channel (struct channel, chan->ppp) that ppp_input() dereferences. The pppox socket is SOCK_R…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/06213c85d8c0994f786c093b8b2a517987943ca6
- https://git.kernel.org/stable/c/3ab32218d7182705dae5c86f13925f458072da2c
- https://git.kernel.org/stable/c/4bb84e964ff0fe0a171c965362de72f9820dbce9
- https://git.kernel.org/stable/c/c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa
- https://git.kernel.org/stable/c/ec4215683e47424c9c4762fd3c60f552a3119142
Timeline
- nvd_ingest NVD