I get the same problem:

Subject: linux 6.8.0-146.146-generic (noble): use-after-free in
l2tp_core on L2TP/IPsec (NAT-T) connect, followed by kernel panic within
minutes; regression from 6.8.0-142

Package: linux-image-6.8.0-146-generic 6.8.0-146.146
Release: Ubuntu 24.04.5 LTS (noble)
Kernel:  Ubuntu 6.8.0-146.146-generic 6.8.12 (/proc/version_signature)
Arch:    x86_64


SUMMARY
-------
Upgraded from 6.8.0-142 to 6.8.0-146, connecting an L2TP/IPsec VPN
(NetworkManager-l2tp + strongSwan, NAT-T / UDP-encapsulated ESP). Got a
use-after-free on the L2TP session object in l2tp_core. The refcount warnings
happened within ~3 seconds of the tunnel coming up. Minutes later, a received 
VPN
packet makes l2tp_tunnel_get_session() dereference a garbage pointer and the
machine panics in interrupt context ("Fatal exception in interrupt"). The
machine freezes: with kernel.panic=0

This reproduced on both connection attempt on 6.8.0-146. The same
VPN configuration was used on 6.8.0-142 from 2026-09-24 to 2026-10-02 with
multi-day sessions and no kernel warnings or crashes.


REGRESSION EVIDENCE
-------------------
Boot kernel history (journalctl --list-boots, "Linux version" line):

  boot -4  6.8.0-139-generic   (VPN used, stable)
  boot -3  6.8.0-142-generic   (VPN used, stable)
  boot -2  6.8.0-146-generic   2026-10-02 VPN started at 23:20; crash
  boot -1  6.8.0-146-generic   crash at 23:32 (panic captured in pstore)

STEPS TO REPRODUCE
------------------
1. Ubuntu 24.04 on 6.8.0-146-generic, network-manager-l2tp 1.20.12,
   strongswan-starter 5.9.13, xl2tpd 1.3.18, ppp 2.4.9.
2. Machine is behind NAT (IKE shows "local host is behind NAT", NAT-T
   on UDP/4500).
3. Connect an L2TP/IPsec (PSK, main mode, ESP AES_CBC_256/HMAC_SHA1_96,
   transport mode) VPN through NetworkManager.
4. Observe refcount_t warnings in the kernel log immediately after ppp0 comes
   up, then (some minutes later, as traffic flows over the VPN) a page fault
   and panic.

TIMELINE OF THE SECOND CRASH (boot -1; times are uptime)
---------------------------------------------------------
  ~355 s   VPN connects; ppp0 appears.
  355.158  refcount_t: addition on 0; use-after-free.
  355.159  refcount_t: underflow; use-after-free.
  355.677  refcount_t: saturated; leaking memory.
  ...      machine keeps running ~5 minutes with VPN traffic.
  665.753  BUG: unable to handle page fault for address: 00000032ffffffd1
  665.839  Kernel panic - not syncing: Fatal exception in interrupt

(The page-fault address and RBX = 00000032ffffffa9 are not valid kernel
pointers; this looks like a corrupted/freed hlist node in the session hash
being walked.)


TRACE 1:, same on both crashes
-----------------------------------------------------------------------
refcount_t: addition on 0; use-after-free.
WARNING: CPU: 9 PID: 122 at lib/refcount.c:25 refcount_warn_saturate+0x12e/0x150
CPU: 9 PID: 122 Comm: kworker/9:1 Tainted: P        OE  6.8.0-146-generic 
#146-Ubuntu
Hardware name: MSI MS-7885/X99A SLI PLUS(MS-7885), BIOS 1.D0 07/15/2016
Workqueue: events xfrm_trans_reinject
Call Trace:
 <TASK>
 l2tp_tunnel_get_session+0xc8/0xd0 [l2tp_core]
 l2tp_udp_recv_core+0xb1/0x350 [l2tp_core]
 l2tp_udp_encap_recv+0x2c/0x54 [l2tp_core]
 udp_queue_rcv_one_skb+0x27b/0x550
 udp_queue_rcv_skb+0x4f/0x80
 udp_unicast_rcv_skb+0x7a/0xa0
 __udp4_lib_rcv+0x627/0x6f0
 udp_rcv+0x25/0x40
 ip_protocol_deliver_rcu+0xd8/0x210
 ip_local_deliver_finish+0x77/0xa0
 ip_local_deliver+0x6e/0x120
 xfrm4_rcv_encap_finish2+0x3c/0x60
 xfrm_trans_reinject+0xe5/0x170
 process_one_work+0x184/0x3a0
 worker_thread+0x18b/0x330
 kthread+0xf2/0x120
 ret_from_fork+0x47/0x70
 ret_from_fork_asm+0x1b/0x30
 </TASK>

Immediately followed by "refcount_t: underflow; use-after-free." from
l2tp_session_dec_refcount+0xbb/0xd0 [l2tp_core] called from
l2tp_udp_recv_core+0x103/0x350, and "refcount_t: saturated; leaking memory."
from l2tp_tunnel_get_session+0xbc/0xd0 (same call chain).


TRACE 2: fatal oops and panic (captured from EFI pstore; journald could not
flush to disk before the machine froze)
----------------------------------------------------------------------------
BUG: unable to handle page fault for address: 00000032ffffffd1
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1] PREEMPT SMP PTI
Workqueue: events xfrm_trans_reinject
RIP: 0010:l2tp_tunnel_get_session+0x38/0xd0 [l2tp_core]
RSP: 0000:ffffcdc1cff9bc00 EFLAGS: 00010206
RAX: 0000000000000006 RBX: 00000032ffffffa9 RCX: 0000000000000002
RDX: 0000000000000046 RSI: 00000000000036d9 RDI: ffff8b7881e76400
RBP: ffffcdc1cff9bc08 R08: 0000000000000002 R09: 0000000000000046
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8b7bcf2ed48a
R13: 00000000000036d9 R14: ffff8b7bcf2ed490 R15: ffff8b7881e76400
CR2: 00000032ffffffd1
Call Trace:
 <TASK>
 l2tp_udp_recv_core+0xb1/0x350 [l2tp_core]
 l2tp_udp_encap_recv+0x2c/0x54 [l2tp_core]
 udp_queue_rcv_one_skb+0x27b/0x550
 udp_queue_rcv_skb+0x4f/0x80
 udp_unicast_rcv_skb+0x7a/0xa0
 __udp4_lib_rcv+0x627/0x6f0
 udp_rcv+0x25/0x40
 ip_protocol_deliver_rcu+0xd8/0x210
 ip_local_deliver_finish+0x77/0xa0
 ip_local_deliver+0x6e/0x120
 xfrm4_rcv_encap_finish2+0x3c/0x60
 xfrm_trans_reinject+0xe5/0x170
 process_one_work+0x184/0x3a0
 worker_thread+0x18b/0x330
 kthread+0xf2/0x120
 ret_from_fork+0x47/0x70
 ret_from_fork_asm+0x1b/0x30
 </TASK>
Kernel panic - not syncing: Fatal exception in interrupt
Kernel Offset: 0x2e000000 from 0xffffffff81000000


FIRST CRASH (boot -2): same refcount warnings at 23:19:05, then
-------------------------------------------------------------
general protection fault, probably for non-canonical address 0x3be9bac37915b95d
RIP: 0010:__kmalloc+0x15b/0x4f0
...followed by repeated
WARNING: net/l2tp/l2tp_ppp.c:166 pppol2tp_xmit+0x1e1/0x220 [l2tp_ppp]
(call path ppp_push <- ppp_send_frame <- ... <- udp_sendmsg from
systemd-resolve), kernel tainted D, and then the machine hung. SysRq
Emergency Sync was logged once at 23:20:48 and the machine was reset.
(The __kmalloc fault in an unrelated allocator is consistent with slab
corruption from the same use-after-free.)


ADDITIONAL NOTES
----------------
- The faulting path is the receive side: ESP-in-UDP (NAT-T) packet is
  decrypted and requeued via xfrm_trans_reinject() in a kworker, then
  delivered to the L2TP UDP encap receive handler l2tp_udp_encap_recv().
  The warnings fire in l2tp_udp_recv_core() on the session lookup/release
  (l2tp_tunnel_get_session / l2tp_session_dec_refcount), i.e. it looks like
  a session reference being taken after the last reference was dropped.

POSSIBLE ROOT CAUSES

------------------------------------------------------------------------
All come from "Noble update: upstream stable patchset 2026-08-21
(LP: #2164796)", new in 6.8.0-146 and absent from 6.8.0-142:

  l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
        (CVE-2026-53262) -- touches the L2TP session refcount directly
  xfrm: input: hold netns during deferred transport reinjection
        -- the xfrm_trans_reinject() workqueue is the entry point in both
           of my traces
  xfrm: hold dev ref until after transport_finish NF_HOOK
        (CVE-2026-31663)
  xfrm: hold device only for the asynchronous decryption


** CVE added: https://cve.org/CVERecord?id=CVE-2026-31663

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169269

Title:
  l2tp_core: refcount_t "addition on 0; use-after-free" in
  l2tp_tunnel_get_session on every L2TP/IPsec connect, system freezes
  (regression 6.8.0-142 -> 6.8.0-146, noble)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169269/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to