A flaw was found in the Linux kernel's Layer 2 Tunneling...
Moderate severity
Unreviewed
Published
Nov 29, 2022
to the GitHub Advisory Database
•
Updated May 3, 2023
Description
Published by the National Vulnerability Database
Nov 28, 2022
Published to the GitHub Advisory Database
Nov 29, 2022
Last updated
May 3, 2023
A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a denial of service.
References