l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
Published Jun 25, 2026
7.8
HIGHCVSS 3.1
EPSS 0.12%
Description
pppol2tp_ioctl() read sock->sk->sk_user_data directly without any locks or reference counting. If a controllable sleep was induced during copy_from_user() (e.g. via a userfaultfd page fault sleep), a concurrent socket close could trigger pppol2tp_session_close() asynchronously. This frees the l2tp_session structure via the l2tp_session_del_work workqueue. Upon resuming, the ioctl thread dereferences the stale session pointer, resulting in a Use-After-Free (UAF).
Fix this by securely fetching the session reference using the RCU-safe, refcounted helper pppol2tp_sock_to_session(sk) on entry. This locks the session's refcount across the sleep. We structured the function to exit via standard err breaks, guaranteeing that l2tp_session_put() is cleanly called on all return paths to drop the reference.
To preserve existing behavior we validate the session and its magic signature only for the specific L2TP commands that require it. This ensures that generic/unknown ioctls called on an unconnected socket still return -ENOIOCTLCMD and correctly fall back to generic handlers (e.g. in sock_do_ioctl()).
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.35StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.35
- Version 6.12.94StatusunaffectedConstraints<=6.12.*
- Version 6.18.36StatusunaffectedConstraints<=6.18.*
- Version 7.0.13StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 2.6.35 · < 6.12.94
- ≥ 6.13 · < 6.18.36
- ≥ 6.19 · < 7.0.13
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Jun–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.12% (0.00119) | 1.59th | v5 (v2026.06.15) |
| Jun 25, 2026 | 0.16% (0.00163) | 5.85th | v5 (v2026.06.15) |
References (9)
- https://access.redhat.com/security/cve/CVE-2026-53262 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492784 Issue Tracking
- https://git.kernel.org/stable/c/62f327e287cf7b595ae3f73ba72f5cd2a9e9f39f Patch
- https://git.kernel.org/stable/c/78cdfdca88cbf731a92f3b9ee5427c633dd94e28 Patch
- https://git.kernel.org/stable/c/a213a8950414c684999dcf03edeea6c46ede172e Patch
- https://git.kernel.org/stable/c/e251d4cdfc725c9e7d686161e3b775a0e7d95053 Patch
- https://lore.kernel.org/linux-cve-announce/2026062516-CVE-2026-53262-3892@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53262
- https://www.cve.org/CVERecord?id=CVE-2026-53262
Change history (0)
No recorded changes yet.