PT-2024-35658 · Linux · Linux Kernel

Syzbot

·

Published

2024-11-26

·

Updated

2025-01-01

·

CVE-2024-53211

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability has been resolved in the Linux kernel. The issue is related to the net/l2tp module, specifically in the l2tp exit net function. The problem occurs when the IDR (ID Resolver) is not properly checked for emptiness before destruction, potentially leading to a warning. This is caused by the radix tree of the IDR containing internal radix-tree nodes, which are cleaned by idr destroy. The vulnerability can be provoked by forcing memory allocation failures in idr alloc 32.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Improper Resource Release

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-04531
CVE-2024-53211

Affected Products

Linux Kernel