Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
2017-03-07T21:59:00.153
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 7.0 (HIGH)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 3.2 | Yes |
Operating System | linux | linux_kernel | < 3.2.88 | Yes |
Operating System | linux | linux_kernel | < 3.12.69 | Yes |
Operating System | linux | linux_kernel | < 3.16.40 | Yes |
Operating System | linux | linux_kernel | < 3.18.52 | Yes |
Operating System | linux | linux_kernel | < 4.4.38 | Yes |
Operating System | linux | linux_kernel | < 4.8.14 | Yes |
Operating System | android | ≤ 7.1.1 | Yes |