CVE-2024-49940

Source
https://cve.org/CVERecord?id=CVE-2024-49940
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49940.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-49940
Downstream
AZL (2)
BELL (1)
DEBIAN (1)
ECHO (1)
OESA (4)
openSUSE (2)
ROOT (4)
SUSE (9)
UBUNTU (1)
Related
Published
2024-10-21T18:01:59Z
Modified
2026-10-08T02:48:48Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
l2tp: prevent possible tunnel refcount underflow
Details

In the Linux kernel, the following vulnerability has been resolved:

l2tp: prevent possible tunnel refcount underflow

When a session is created, it sets a backpointer to its tunnel. When the session refcount drops to 0, l2tp_session_free drops the tunnel refcount if session->tunnel is non-NULL. However, session->tunnel is set in l2tp_session_create, before the tunnel refcount is incremented by l2tp_session_register, which leaves a small window where session->tunnel is non-NULL when the tunnel refcount hasn't been bumped.

Moving the assignment to l2tp_session_register is trivial but l2tp_session_create calls l2tp_session_set_header_len which uses session->tunnel to get the tunnel's encap. Add an encap arg to l2tp_session_set_header_len to avoid using session->tunnel.

If l2tpv3 sessions have colliding IDs, it is possible for l2tp_v3_session_get to race with l2tp_session_register and fetch a session which doesn't yet have session->tunnel set. Add a check for this case.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49940.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3953ae7b218df4d1e544b98a393666f9ae58a78c
Fixed
f7415e60c25a6108cd7955a20b2e66b6251ffe02
Fixed
24256415d18695b46da06c93135f5b51c548b950
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.2.99
Fixed
3.3
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3.16.54
Fixed
3.17
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.4.225
Fixed
4.5
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.9.225
Fixed
4.10
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.14.182
Fixed
4.15
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b102bfc2a90d14f342580285782a9a51c74f7369
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
10c15ddabbcf888922adbdd44ca3fecf6eab19d9
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8d1c650d452c53fcb3f02a7b1d772741639f89a4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
12b5fb58ac993c24210cf8cbc72d407d3a4e6490
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
aef37401b467a0b1a9517c69924a1d66937e0789

Affected versions

v3.*
v3.16.54
v3.16.55
v3.16.56
v3.16.57
v3.16.58
v3.16.59
v3.16.60
v3.16.61
v3.16.62
v3.16.63
v3.16.64
v3.16.65
v3.16.66
v3.16.67
v3.16.68
v3.16.69
v3.16.70
v3.16.71
v3.16.72
v3.16.73
v3.16.74
v3.16.75
v3.16.76
v3.16.77
v3.16.78
v3.16.79
v3.16.80
v3.16.81
v3.16.82
v3.16.83
v3.16.84
v3.16.85
v3.2.100
v3.2.101
v3.2.102
v3.2.99
v4.*
v4.14.182
v4.14.183
v4.14.184
v4.14.185
v4.14.186
v4.14.187
v4.14.188
v4.14.189
v4.14.190
v4.14.191
v4.14.192
v4.14.193
v4.14.194
v4.14.195
v4.14.196
v4.14.197
v4.14.198
v4.14.199
v4.14.200
v4.14.201
v4.14.202
v4.14.203
v4.14.204
v4.14.205
v4.14.206
v4.14.207
v4.14.208
v4.14.209
v4.14.210
v4.14.211
v4.14.212
v4.14.213
v4.14.214
v4.14.215
v4.14.216
v4.14.217
v4.14.218
v4.14.219
v4.14.220
v4.14.221
v4.14.222
v4.14.223
v4.14.224
v4.14.225
v4.14.226
v4.14.227
v4.14.228
v4.14.229
v4.14.230
v4.14.231
v4.14.232
v4.14.233
v4.14.234
v4.14.235
v4.14.236
v4.14.237
v4.14.238
v4.14.239
v4.14.240
v4.14.241
v4.14.242
v4.14.243
v4.14.244
v4.14.245
v4.14.246
v4.14.247
v4.14.248
v4.14.249
v4.14.250
v4.14.251
v4.14.252
v4.14.253
v4.14.254
v4.14.255
v4.14.256
v4.14.257
v4.14.258
v4.14.259
v4.14.260
v4.14.261
v4.14.262
v4.14.263
v4.14.264
v4.14.265
v4.14.266
v4.14.267
v4.14.268
v4.14.269
v4.14.270
v4.14.271
v4.14.272
v4.14.273
v4.14.274
v4.14.275
v4.14.276
v4.14.277
v4.14.278
v4.14.279
v4.14.280
v4.14.281
v4.14.282
v4.14.283
v4.14.284
v4.14.285
v4.14.286
v4.14.287
v4.14.288
v4.14.289
v4.14.290
v4.14.291
v4.14.292
v4.14.293
v4.14.294
v4.14.295
v4.14.296
v4.14.297
v4.14.298
v4.14.299
v4.14.300
v4.14.301
v4.14.302
v4.14.303
v4.14.304
v4.14.305
v4.14.306
v4.14.307
v4.14.308
v4.14.309
v4.14.310
v4.14.311
v4.14.312
v4.14.313
v4.14.314
v4.14.315
v4.14.316
v4.14.317
v4.14.318
v4.14.319
v4.14.320
v4.14.321
v4.14.322
v4.14.323
v4.14.324
v4.14.325
v4.14.326
v4.14.327
v4.14.328
v4.14.329
v4.14.330
v4.14.331
v4.14.332
v4.14.333
v4.14.334
v4.14.335
v4.14.336
v4.4.225
v4.4.226
v4.4.227
v4.4.228
v4.4.229
v4.4.230
v4.4.231
v4.4.232
v4.4.233
v4.4.234
v4.4.235
v4.4.236
v4.4.237
v4.4.238
v4.4.239
v4.4.240
v4.4.241
v4.4.242
v4.4.243
v4.4.244
v4.4.245
v4.4.246
v4.4.247
v4.4.248
v4.4.249
v4.4.250
v4.4.251
v4.4.252
v4.4.253
v4.4.254
v4.4.255
v4.4.256
v4.4.257
v4.4.258
v4.4.259
v4.4.260
v4.4.261
v4.4.262
v4.4.263
v4.4.264
v4.4.265
v4.4.266
v4.4.267
v4.4.268
v4.4.269
v4.4.270
v4.4.271
v4.4.272
v4.4.273
v4.4.274
v4.4.275
v4.4.276
v4.4.277
v4.4.278
v4.4.279
v4.4.280
v4.4.281
v4.4.282
v4.4.283
v4.4.284
v4.4.285
v4.4.286
v4.4.287
v4.4.288
v4.4.289
v4.4.290
v4.4.291
v4.4.292
v4.4.293
v4.4.294
v4.4.295
v4.4.296
v4.4.297
v4.4.298
v4.4.299
v4.4.300
v4.4.301
v4.4.302
v4.9.225
v4.9.226
v4.9.227
v4.9.228
v4.9.229
v4.9.230
v4.9.231
v4.9.232
v4.9.233
v4.9.234
v4.9.235
v4.9.236
v4.9.237
v4.9.238
v4.9.239
v4.9.240
v4.9.241
v4.9.242
v4.9.243
v4.9.244
v4.9.245
v4.9.246
v4.9.247
v4.9.248
v4.9.249
v4.9.250
v4.9.251
v4.9.252
v4.9.253
v4.9.254
v4.9.255
v4.9.256
v4.9.257
v4.9.258
v4.9.259
v4.9.260
v4.9.261
v4.9.262
v4.9.263
v4.9.264
v4.9.265
v4.9.266
v4.9.267
v4.9.268
v4.9.269
v4.9.270
v4.9.271
v4.9.272
v4.9.273
v4.9.274
v4.9.275
v4.9.276
v4.9.277
v4.9.278
v4.9.279
v4.9.280
v4.9.281
v4.9.282
v4.9.283
v4.9.284
v4.9.285
v4.9.286
v4.9.287
v4.9.288
v4.9.289
v4.9.290
v4.9.291
v4.9.292
v4.9.293
v4.9.294
v4.9.295
v4.9.296
v4.9.297
v4.9.298
v4.9.299
v4.9.300
v4.9.301
v4.9.302
v4.9.303
v4.9.304
v4.9.305
v4.9.306
v4.9.307
v4.9.308
v4.9.309
v4.9.310
v4.9.311
v4.9.312
v4.9.313
v4.9.314
v4.9.315
v4.9.316
v4.9.317
v4.9.318
v4.9.319
v4.9.320
v4.9.321
v4.9.322
v4.9.323
v4.9.324
v4.9.325
v4.9.326
v4.9.327
v4.9.328
v4.9.329
v4.9.330
v4.9.331
v4.9.332
v4.9.333
v4.9.334
v4.9.335
v4.9.336
v4.9.337

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49940.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
6.11.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49940.json"