In the Linux kernel, the following vulnerability has been resolved:
l2tp: use list_del_rcu in l2tp_session_unhash
An unprivileged local user can pin a host CPU indefinitely in l2tp_session_get_by_ifname() by issuing L2TP_CMD_SESSION_GET on L2TP_ATTR_IFNAME concurrently with L2TP_CMD_SESSION_CREATE and L2TP_CMD_SESSION_DELETE on the same tunnel. All three commands take GENL_UNS_ADMIN_PERM, so CAP_NET_ADMIN in the netns user namespace suffices; on any host that has l2tp_core loaded the trigger is reachable from a standard `unshare -Urn` sandbox.
l2tp_session_unhash() removes a session from tunnel->session_list with list_del_init(), but that list is walked by l2tp_session_get_by_ifname() with list_for_each_entry_rcu() under rcu_read_lock_bh(). list_del_init() leaves the deleted entry's next/prev self-pointing; a reader that has loaded the entry and then advances pos->list.next reads &session->list, container_of()s back to the same session, and list_for_each_entry_rcu() never reaches the list head. The CPU stays in strcmp() inside the walker, with BH and preemption disabled, so RCU grace periods on the host stall behind it and the wedged thread cannot be killed (SIGKILL is delivered on syscall return).
Use list_del_rcu() to match the existing list_add_rcu() in l2tp_session_register(); the deleted session remains visible to in-flight walkers with consistent next/prev pointers until kfree_rcu() in l2tp_session_free() releases it. tunnel->session_list has exactly one list_del_init() call site; the list_del_init (&session->clist) at l2tp_core.c:533 operates on the per-collision list, which is not walked under RCU. list_empty(&session->list) is not used anywhere in net/l2tp/ after the unhash point, so dropping the post-delete self-init is safe; the fix has no userspace-visible behavior change.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Ubuntu | — | Upgrade linux-image-nvidia-64kUpgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-nvidia-7.0Upgrade linux-image-raspiUpgrade linux-image-azure-fde-7.0Upgrade linux-image-raspi-7.0Upgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-awsUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-oracle-64kUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-raspi-realtimeUpgrade linux-image-nvidia-bosUpgrade linux-image-ibmUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-gcpUpgrade linux-image-azure-7.0Upgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-oracle-7.0Upgrade linux-image-azure-fdeUpgrade linux-image-gcp-7.0Upgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-azureUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-7.0.0-1014-azureUpgrade linux-image-7.0.0-1010-azureUpgrade linux-image-gcp-64kUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-aws-7.0Upgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-oracleUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-nvidiaUpgrade linux-image-aws-64k-7.0Upgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-ibm-7.0Upgrade linux-image-aws-64kUpgrade linux-image-7.0.0-1010-ibm | Jul 21, 2026 | Jul 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 3, 2026 | Jul 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub