Linux Kernel Signed Integer Overflow Vulnerability in IPv6 L2TP Message Handling

Vulnerability

A signed integer overflow vulnerability has been identified in the Linux kernel's IPv6 L2TP message handling. When the length parameter is greater than or equal to INT_MAX minus the length of the transport header, the calculation of the total length can overflow. This issue has been addressed by modifying the length calculation to align with the approach used for UDP over IPv6.

Impact

Exploitation of this vulnerability could lead to a signed integer overflow, potentially allowing for buffer overflows or other unintended behavior.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.