kernel: net: pppol2tp: level handling in pppol2tp_[s,g]etsockopt()
Published Jul 19, 2014
6.9
MEDIUMCVSS 2.0
EPSS 2.10%
Description
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
Affected products
No data.
Configuration 1
- ≥ 2.6.23 · < 3.2.62
- ≥ 3.3 · < 3.4.102
- ≥ 3.5 · < 3.10.52
- ≥ 3.11 · < 3.12.27
- ≥ 3.13 · < 3.14.16
- ≥ 3.15 · < 3.15.9
Configuration 2
- 11.4
- 11
- 11
- 11
- 11
Configuration 3
- 6.2
Configuration 4
- 7.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-431.20.5.el6
Fixed · RHSA-2014:0924
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.54.1.el6
Fixed · RHSA-2014:1025
Red Hat Enterprise Linux 6.4 Extended Update Support
kernel-0:2.6.32-358.46.2.el6
Fixed · RHSA-2014:0925
Red Hat Enterprise Linux 7
kernel-0:3.10.0-123.4.4.el7
Fixed · RHSA-2014:0923
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-431.20.5.el6 | Fixed | RHSA-2014:0924 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.54.1.el6 | Fixed | RHSA-2014:1025 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | kernel-0:2.6.32-358.46.2.el6 | Fixed | RHSA-2014:0925 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-123.4.4.el7 | Fixed | RHSA-2014:0923 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2. Please note that on Red Hat Enterprise Linux 6 pppol2tp module is not automatically loaded when AF_PPPOX/PX_PROTO_OL2TP socket is created as Red Hat Enterprise Linux 6 lacks upstream commit 9395a09d05a23bb and default modprobe configuration as shipped with module-init-tools package does not contain the alias for pppol2tp protocol either. As a result, pppol2tp module has to be explicitly enabled and/or loaded by the system administrator.
Red Hat mitigation
For Red Hat Enterprise Linux 6 do -- ]# echo "install pppol2tp /bin/true" > /etc/modprobe.d/pppol2tp.conf For Red Hat Enterprise Linux 7 do -- ]# echo "install l2tp_ppp /bin/true" > /etc/modprobe.d/l2t_pppp.conf Or, alternatively, when pppol2tp/l2tp_ppp module can't be blacklisted and needs to be loaded, you can use the following systemtap script -- 1) On the host, save the following in a file with the ".stp" extension -- probe module("*l2tp*").function("pppol2tp_*etsockopt").call { $level = 273; } 2) Install the "systemtap" package and any required dependencies. Refer to the "2. Using SystemTap" chapter in the Red Hat Enterprise Linux 6 "SystemTap Beginners Guide" document, available from docs.redhat.com, for information on installing the required -debuginfo packages. 3) Run the "stap -g [filename-from-step-1].stp" command as root. If the host is rebooted, the changes will be lost and the script must be run again. Alternatively, build the systemtap script on a development system with "stap -g -p 4 [filename-from-step-1].stp", distribute the resulting kernel module to all affected systems, and run "staprun -L <module>" on those. When using this approach only systemtap-runtime package is required on the affected systems. Please notice that the kernel version must be the same across all systems.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.10% (0.02103) | 81.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.10% (0.02103) | 79.25th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.54% (0.01537) | 79.63th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.20% (0.05201) | 82.83th | v4 (v2025.03.14) |
| Mar 28, 2025 | 1.54% (0.01537) | 79.63th | v4 (v2025.03.14) |
| Mar 27, 2025 | 5.20% (0.05201) | 88.50th | v4 (v2025.03.14) |
| Mar 20, 2025 | 1.54% (0.01537) | 79.72th | v4 (v2025.03.14) |
| Mar 19, 2025 | 5.20% (0.05201) | 88.66th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.54% (0.01537) | 80.06th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 0.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 0.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.82% (0.03821) | 85.56th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.82% (0.03821) | 84.08th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.82% (0.03821) | 67.27th | v2 (v2022.01.01) |
References (26)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3cf521f7dc87c031617fd47e4b7aa2593c2f3daf x_refsource_CONFIRMBroken LinkThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-0924.html x_refsource_CONFIRMThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3047.html x_refsource_CONFIRMThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3048.html x_refsource_CONFIRMThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2014/07/17/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://osvdb.org/show/osvdb/109277 vdb-entryx_refsource_OSVDBBroken Link
- http://rhn.redhat.com/errata/RHSA-2014-1025.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/59790 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/60011 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/60071 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/60220 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/60380 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/60393 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.debian.org/security/2014/dsa-2992 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.exploit-db.com/exploits/36267 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030610 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2014-4943 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1119458 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94665 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://github.com/torvalds/linux/commit/3cf521f7dc87c031617fd47e4b7aa2593c2f3daf x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-4943
- https://www.cve.org/CVERecord?id=CVE-2014-4943
Change history (0)
No recorded changes yet.