A flaw was found in the Linux kernel's Layer 2 Tunneling...
Moderate severity
Unreviewed
Published
Nov 29, 2022
to the GitHub Advisory Database
•
Updated Apr 14, 2025
Description
Published by the National Vulnerability Database
Nov 28, 2022
Published to the GitHub Advisory Database
Nov 29, 2022
Last updated
Apr 14, 2025
A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a denial of service.
References