PT-2026-95076 · Unknown · Networkmanager-L2Tp
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NetworkManager-l2tp (affected versions not specified)
Description
Improper input validation allows local users with VPN connection creation permissions to inject arbitrary pppd directives. By providing
mru or mtu property values that contain non-numeric content following a valid integer, an attacker can exploit the write config option() function, which writes unvalidated strings directly into the pppd options file. This allows the injection of a plugin directive, leading the privileged pppd process to load a malicious shared object and execute arbitrary code with root privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Networkmanager-L2Tp