ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 7.8epss 0.2%
de la publicación al arma2 días
Publicada en NVD10 ago
1ª PoC+2d
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
In the Linux kernel, the following vulnerability has been resolved:
ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:
l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv()
-> ppp_input(&po->chan)
It runs under rcu_read_lock() holding only an l2tp_session reference and
takes NO reference on the internal PPP channel (struct channel,
chan->ppp) that ppp_input() dereferences.
The pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel
are RCU-safe. But the internal struct channel is a separate allocation
that ppp_release_channel() frees with a plain kfree():
close(data socket) -> pppol2tp_release() -> pppox_unbind_sock()
-> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch)
For a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit
(no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips
both ppp_disconnect_channel()'s synchronize_net() and
ppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace
period. rcu_read_lock() in pppol2tp_recv() does not protect against a
plain kfree(), so an in-flight ppp_input() on one CPU can dereference
the channel just freed by close() on another CPU.
The bug is reachable by an unprivileged user.
Defer the channel free to an RCU callback via call_rcu() so the grace
period fences any in-flight ppp_input(). The disconnect and unbridge
teardown paths already fence with synchronize_net()/synchronize_rcu();
call_rcu() does the same here without stalling the close() path.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Linux · LinuxPoCs públicas encontradas — 1
githubgithub.com/aramosf/CVE-2026-68398★ 10⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://git.kernel.org/stable/c/06213c85d8c0994f786c093b8b2a517987943ca6https://git.kernel.org/stable/c/110b765744b147c63882f5e9cb12931c5dc8d85fhttps://git.kernel.org/stable/c/3ab32218d7182705dae5c86f13925f458072da2chttps://git.kernel.org/stable/c/4bb84e964ff0fe0a171c965362de72f9820dbce9https://git.kernel.org/stable/c/4e47f1ac188ece11d6fdabe44166a2776cc5bd4ehttps://git.kernel.org/stable/c/c9574b8a8edeb4edd3ac6472c27ef7184bdb2baahttps://git.kernel.org/stable/c/ec4215683e47424c9c4762fd3c60f552a3119142