Possible duplicate / same regression: I filed bug #2169477
(https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169477) on
2026-10-04 for what looks like the same defect -- same boundary
(6.8.0-142 good, 6.8.0-146 bad, noble), same refcount_t "addition on 0;
use-after-free" on an L2TP session object, same L2TP-over-IPsec trigger.

Your trace surfaces in l2tp_tunnel_get_session() via xfrm_trans_reinject();
on my host the only changed l2tp object between -142 and -146 is
l2tp_ppp.ko (l2tp_core.ko is identical), and I suspect the session
refcount handling in pppol2tp_ioctl() touched by the CVE-2026-53262
backport. My report has 11 EFI pstore dumps attached if they are useful
for comparison.

One data point that may narrow the trigger: the hang only occurs once an
L2TP session is actually established. Behind NAT, where strongSwan never
completes and no session is created, the same box on the same -146
kernel stayed up 12-17 minutes with no splat; on a public uplink with
ppp0 up at ~19 s it died 46 s and 108 s into boot.


** CVE added: https://cve.org/CVERecord?id=CVE-2026-53262

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169269

Title:
  l2tp_core: refcount_t "addition on 0; use-after-free" in
  l2tp_tunnel_get_session on every L2TP/IPsec connect, system freezes
  (regression 6.8.0-142 -> 6.8.0-146, noble)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169269/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to