I get the same problem:
Subject: linux 6.8.0-146.146-generic (noble): use-after-free in
l2tp_core on L2TP/IPsec (NAT-T) connect, followed by kernel panic within
minutes; regression from 6.8.0-142
Package: linux-image-6.8.0-146-generic 6.8.0-146.146
Release: Ubuntu 24.04.5 LTS (noble)
Kernel: Ubuntu 6.8.0-146.146-generic 6.8.12 (/proc/version_signature)
Arch: x86_64
SUMMARY
-------
Upgraded from 6.8.0-142 to 6.8.0-146, connecting an L2TP/IPsec VPN
(NetworkManager-l2tp + strongSwan, NAT-T / UDP-encapsulated ESP). Got a
use-after-free on the L2TP session object in l2tp_core. The refcount warnings
happened within ~3 seconds of the tunnel coming up. Minutes later, a received
VPN
packet makes l2tp_tunnel_get_session() dereference a garbage pointer and the
machine panics in interrupt context ("Fatal exception in interrupt"). The
machine freezes: with kernel.panic=0
This reproduced on both connection attempt on 6.8.0-146. The same
VPN configuration was used on 6.8.0-142 from 2026-09-24 to 2026-10-02 with
multi-day sessions and no kernel warnings or crashes.
REGRESSION EVIDENCE
-------------------
Boot kernel history (journalctl --list-boots, "Linux version" line):
boot -4 6.8.0-139-generic (VPN used, stable)
boot -3 6.8.0-142-generic (VPN used, stable)
boot -2 6.8.0-146-generic 2026-10-02 VPN started at 23:20; crash
boot -1 6.8.0-146-generic crash at 23:32 (panic captured in pstore)
STEPS TO REPRODUCE
------------------
1. Ubuntu 24.04 on 6.8.0-146-generic, network-manager-l2tp 1.20.12,
strongswan-starter 5.9.13, xl2tpd 1.3.18, ppp 2.4.9.
2. Machine is behind NAT (IKE shows "local host is behind NAT", NAT-T
on UDP/4500).
3. Connect an L2TP/IPsec (PSK, main mode, ESP AES_CBC_256/HMAC_SHA1_96,
transport mode) VPN through NetworkManager.
4. Observe refcount_t warnings in the kernel log immediately after ppp0 comes
up, then (some minutes later, as traffic flows over the VPN) a page fault
and panic.
TIMELINE OF THE SECOND CRASH (boot -1; times are uptime)
---------------------------------------------------------
~355 s VPN connects; ppp0 appears.
355.158 refcount_t: addition on 0; use-after-free.
355.159 refcount_t: underflow; use-after-free.
355.677 refcount_t: saturated; leaking memory.
... machine keeps running ~5 minutes with VPN traffic.
665.753 BUG: unable to handle page fault for address: 00000032ffffffd1
665.839 Kernel panic - not syncing: Fatal exception in interrupt
(The page-fault address and RBX = 00000032ffffffa9 are not valid kernel
pointers; this looks like a corrupted/freed hlist node in the session hash
being walked.)
TRACE 1:, same on both crashes
-----------------------------------------------------------------------
refcount_t: addition on 0; use-after-free.
WARNING: CPU: 9 PID: 122 at lib/refcount.c:25 refcount_warn_saturate+0x12e/0x150
CPU: 9 PID: 122 Comm: kworker/9:1 Tainted: P OE 6.8.0-146-generic
#146-Ubuntu
Hardware name: MSI MS-7885/X99A SLI PLUS(MS-7885), BIOS 1.D0 07/15/2016
Workqueue: events xfrm_trans_reinject
Call Trace:
<TASK>
l2tp_tunnel_get_session+0xc8/0xd0 [l2tp_core]
l2tp_udp_recv_core+0xb1/0x350 [l2tp_core]
l2tp_udp_encap_recv+0x2c/0x54 [l2tp_core]
udp_queue_rcv_one_skb+0x27b/0x550
udp_queue_rcv_skb+0x4f/0x80
udp_unicast_rcv_skb+0x7a/0xa0
__udp4_lib_rcv+0x627/0x6f0
udp_rcv+0x25/0x40
ip_protocol_deliver_rcu+0xd8/0x210
ip_local_deliver_finish+0x77/0xa0
ip_local_deliver+0x6e/0x120
xfrm4_rcv_encap_finish2+0x3c/0x60
xfrm_trans_reinject+0xe5/0x170
process_one_work+0x184/0x3a0
worker_thread+0x18b/0x330
kthread+0xf2/0x120
ret_from_fork+0x47/0x70
ret_from_fork_asm+0x1b/0x30
</TASK>
Immediately followed by "refcount_t: underflow; use-after-free." from
l2tp_session_dec_refcount+0xbb/0xd0 [l2tp_core] called from
l2tp_udp_recv_core+0x103/0x350, and "refcount_t: saturated; leaking memory."
from l2tp_tunnel_get_session+0xbc/0xd0 (same call chain).
TRACE 2: fatal oops and panic (captured from EFI pstore; journald could not
flush to disk before the machine froze)
----------------------------------------------------------------------------
BUG: unable to handle page fault for address: 00000032ffffffd1
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1] PREEMPT SMP PTI
Workqueue: events xfrm_trans_reinject
RIP: 0010:l2tp_tunnel_get_session+0x38/0xd0 [l2tp_core]
RSP: 0000:ffffcdc1cff9bc00 EFLAGS: 00010206
RAX: 0000000000000006 RBX: 00000032ffffffa9 RCX: 0000000000000002
RDX: 0000000000000046 RSI: 00000000000036d9 RDI: ffff8b7881e76400
RBP: ffffcdc1cff9bc08 R08: 0000000000000002 R09: 0000000000000046
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8b7bcf2ed48a
R13: 00000000000036d9 R14: ffff8b7bcf2ed490 R15: ffff8b7881e76400
CR2: 00000032ffffffd1
Call Trace:
<TASK>
l2tp_udp_recv_core+0xb1/0x350 [l2tp_core]
l2tp_udp_encap_recv+0x2c/0x54 [l2tp_core]
udp_queue_rcv_one_skb+0x27b/0x550
udp_queue_rcv_skb+0x4f/0x80
udp_unicast_rcv_skb+0x7a/0xa0
__udp4_lib_rcv+0x627/0x6f0
udp_rcv+0x25/0x40
ip_protocol_deliver_rcu+0xd8/0x210
ip_local_deliver_finish+0x77/0xa0
ip_local_deliver+0x6e/0x120
xfrm4_rcv_encap_finish2+0x3c/0x60
xfrm_trans_reinject+0xe5/0x170
process_one_work+0x184/0x3a0
worker_thread+0x18b/0x330
kthread+0xf2/0x120
ret_from_fork+0x47/0x70
ret_from_fork_asm+0x1b/0x30
</TASK>
Kernel panic - not syncing: Fatal exception in interrupt
Kernel Offset: 0x2e000000 from 0xffffffff81000000
FIRST CRASH (boot -2): same refcount warnings at 23:19:05, then
-------------------------------------------------------------
general protection fault, probably for non-canonical address 0x3be9bac37915b95d
RIP: 0010:__kmalloc+0x15b/0x4f0
...followed by repeated
WARNING: net/l2tp/l2tp_ppp.c:166 pppol2tp_xmit+0x1e1/0x220 [l2tp_ppp]
(call path ppp_push <- ppp_send_frame <- ... <- udp_sendmsg from
systemd-resolve), kernel tainted D, and then the machine hung. SysRq
Emergency Sync was logged once at 23:20:48 and the machine was reset.
(The __kmalloc fault in an unrelated allocator is consistent with slab
corruption from the same use-after-free.)
ADDITIONAL NOTES
----------------
- The faulting path is the receive side: ESP-in-UDP (NAT-T) packet is
decrypted and requeued via xfrm_trans_reinject() in a kworker, then
delivered to the L2TP UDP encap receive handler l2tp_udp_encap_recv().
The warnings fire in l2tp_udp_recv_core() on the session lookup/release
(l2tp_tunnel_get_session / l2tp_session_dec_refcount), i.e. it looks like
a session reference being taken after the last reference was dropped.
POSSIBLE ROOT CAUSES
------------------------------------------------------------------------
All come from "Noble update: upstream stable patchset 2026-08-21
(LP: #2164796)", new in 6.8.0-146 and absent from 6.8.0-142:
l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
(CVE-2026-53262) -- touches the L2TP session refcount directly
xfrm: input: hold netns during deferred transport reinjection
-- the xfrm_trans_reinject() workqueue is the entry point in both
of my traces
xfrm: hold dev ref until after transport_finish NF_HOOK
(CVE-2026-31663)
xfrm: hold device only for the asynchronous decryption
** CVE added: https://cve.org/CVERecord?id=CVE-2026-31663
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169269
Title:
l2tp_core: refcount_t "addition on 0; use-after-free" in
l2tp_tunnel_get_session on every L2TP/IPsec connect, system freezes
(regression 6.8.0-142 -> 6.8.0-146, noble)
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169269/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs