PT-2026-8113 · Linux+2 · Linux Kernel+2

Syzbot

·

Published

2026-01-01

·

Updated

2026-05-22

·

CVE-2026-23120

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a data-race condition within the l2tp tunnel del work() function. This issue arises when handling kernel sockets, specifically during the deletion of an L2TP tunnel. The data-race occurs when accessing sk->sk socket concurrently from different tasks, potentially leading to unpredictable behavior or system instability. The syzbot fuzzer reported the data-race in l2tp tunnel del work and sk common release. The functions involved include sk set socket, sock orphan, sk common release, udp lib close, inet release, sock release, sock close, fput, fput, task work run, resume user mode work, exit to user mode loop, syscall exit to user mode prepare, syscall exit to user mode work, syscall exit to user mode, do syscall 64, and entry SYSCALL 64 after hwframe.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2026-23120
OESA-2026-1760
OPENSUSE-SU-2026:20572-1
SUSE-SU-2026:1573-1
SUSE-SU-2026:1661-1
SUSE-SU-2026:1668-1
SUSE-SU-2026:21114-1
SUSE-SU-2026:21123-1
SUSE-SU-2026:21237-1
SUSE-SU-2026:21255-1
SUSE-SU-2026:21352-1
SUSE-SU-2026:21361-1
USN-8162-1
USN-8180-1
USN-8180-2
USN-8180-3
USN-8180-4
USN-8180-5
USN-8180-6
USN-8186-1
USN-8187-1
USN-8188-1
USN-8243-1
USN-8275-1
USN-8278-1
USN-8289-1
USN-8296-1
USN-8297-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu