SB2017030732 - Privilege escalation in Linux kernel L2TP
Published: March 7, 2017 Updated: August 6, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2016-10200)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://github.com/torvalds/linux/commit/32c231164b762dddefa13af5a0101032c70b50ef
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.14
- http://source.android.com/security/bulletin/2017-03-01.html
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=32c231164b762dddefa13af5a0101032c70b50ef