CVE-2026-93337

NameCVE-2026-93337
DescriptionNetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers can exploit the verbatim write of unvalidated strings into the pppd options file via write_config_option() to inject the plugin directive, causing the privileged pppd process to load an attacker-controlled shared object and achieve arbitrary code execution as root.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4808-1, DSA-6498-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
network-manager-l2tp (PTS)bookworm1.20.8-1vulnerable
bookworm (security)1.20.8-1+deb12u1fixed
trixie1.20.20-2vulnerable
trixie (security)1.20.20-2+deb13u1fixed
forky, sid1.52.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
network-manager-l2tpsourcebookworm1.20.8-1+deb12u1DLA-4808-1
network-manager-l2tpsourcetrixie1.20.20-2+deb13u1DSA-6498-1
network-manager-l2tpsource(unstable)1.52.6-1

Notes

https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-rp84-8h2r-5xc3
Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/64879ce0ad866f7c9a45babe4d95731a916ea00f (1.52.6, 1.20.26)

Search for package or bug name: Reporting problems