Improper Input Validation in NetworkManager-l2tp Plugin by nm-l2tp
CVE-2026-93337
8.5HIGH
What is CVE-2026-93337?
The NetworkManager-l2tp plugin is affected by a vulnerability that stems from improper input validation, enabling local users with VPN connection creation permissions to introduce arbitrary pppd directives. By manipulating the mru or mtu property values to include trailing non-numeric characters, an attacker could exploit a flaw that allows unvalidated strings to be written into the pppd options file. This can lead to a serious risk where the privileged pppd process loads maliciously crafted shared objects, ultimately granting the attacker root access and enabling arbitrary code execution.
Affected Version(s)
NetworkManager-l2tp 0 <= 1.52.4
