VYPR
Medium severity5.5NVD Advisory· Published Dec 27, 2024· Updated Jun 17, 2026

CVE-2024-53211

CVE-2024-53211

Description

In the Linux kernel, the following vulnerability has been resolved:

net/l2tp: fix warning in l2tp_exit_net found by syzbot

In l2tp's net exit handler, we check that an IDR is empty before destroying it:

WARN_ON_ONCE(!idr_is_empty(&pn->l2tp_tunnel_idr)); idr_destroy(&pn->l2tp_tunnel_idr);

By forcing memory allocation failures in idr_alloc_32, syzbot is able to provoke a condition where idr_is_empty returns false despite there being no items in the IDR. This turns out to be because the radix tree of the IDR contains only internal radix-tree nodes and it is this that causes idr_is_empty to return false. The internal nodes are cleaned by idr_destroy.

Use idr_for_each to check that the IDR is empty instead of idr_is_empty to avoid the problem.

Affected products

4
  • Linux/Kernelcpe-rescue3 versions
    6.12+ 2 more
    • (no CPE)range: 6.12
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.12,<6.12.2
    • (no CPE)
  • osv-coords
    Range: >= 6.12.0, < 6.12.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.