Impact
A local unprivileged user can create a custom L2TP VPN profile that injects a newline into the leftupdown directive. NetworkManager‑l2tp writes the unescaped VPN configuration into ipsec.conf, which pluto loads as root during IKE association establishment. The injected command is then executed with root privileges, giving the attacker local privilege escalation. This flaw is an instance of CWE-88, where untrusted data is passed to a parser that can change the program's behavior.
Affected Systems
The vulnerability affects the NetworkManager‑l2tp plugin used by Fedora and Fedora’s Extra Packages for. All versions of the plugin prior to the latest update that includes the input‑escaping fix are potentially vulnerable. No specific product versions are listed in the advisory, so any release that contains an unpatched NetworkManager‑l2tp package must be considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score is < 1%; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have local unprivileged access and the ability to create or edit VPN profiles, a capability normally available to regular users. The attack vector is local, with the attacker crafting a malicious ipsec.conf entry that is processed by pluto with root privileges. The availability of the fix in the current Fedora update stream reduces the window for exploitation when the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA