Back

MEDIUM

kernel: L2TP send buffer allocation size overflows

Published Jan 7, 2011

Description

Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (heap memory corruption and panic) or possibly gain privileges via a crafted sendto call.

Affected products

Remediation

Red Hat statement

The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and 5 did not include L2TP functionality, and therefore are not affected by this issue. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0007.html and https://rhn.redhat.com/errata/RHSA-2011-0330.html.

Metrics

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 7, 2011
Updated Aug 7, 2024
Reserved Nov 4, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Nov 1, 2010