PT-2026-91409 · Fedora+3 · Extra Packages For Enterprise Linux+2
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetworkManager-l2tp (affected versions not specified)
Description
A flaw exists where the plugin writes attacker-controlled VPN connection properties, specifically
vpn.data and vpn.secrets values, unescaped into a generated ipsec.conf file. Because pluto loads this file as root, a local unprivileged user can create and activate an L2TP VPN profile containing a newline-injected leftupdown directive. This allows pluto to execute the injected command as root during the establishment of the IKE security association, leading to local privilege escalation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Extra Packages For Enterprise Linux
Fedora
Networkmanager-L2Tp