Description
In the Linux kernel, the following vulnerability has been resolved:

net: l2tp: do not propagate multicast notification errors

The tunnel create, tunnel modify, session create, and session modify
netlink handlers send multicast notifications through helpers that can fail
while allocating or encoding a message, or while multicasting it.

For tunnel and session create/modify, a notification is sent after the live
operation has completed. Returning a best-effort notification error as the
command result can therefore report failure for an operation that already
committed and can cause callers to retry and accumulate live objects.

Keep sending notifications for listener visibility, but do not propagate
their best-effort status as the command result. This also keeps the tunnel
modify command consistent with the other notification-only paths.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

The Linux kernel L2TP netlink handlers send multicast notifications after tunnel or session creation or modification. When the notification helper fails—whether during allocation, encoding, or multicasting—the legacy code returned that Callers interpret a non‑critical failure as a genuine operation failure and can retry, creating duplicate tunnels or sessions and potentially exhausting kernel resources. This flaw is a classic resource‑allocation weakness (CWE‑770) that results in a low‑severity impact but can lead to a denial‑of‑service if the retry logic is not addressed.

Affected Systems

All Linux kernels that contain the stock L2TP implementation without the commit that suppresses propagation of notification errors are affected. The advisory does not list specific kernel versions, so users should inspect their running kernel version or its build configuration to determine whether the change is present. Distributions that ship the upstream kernel with the L2TP subsystem are included.

Risk and Exploitability

The CVSS score of 4.4 indicates a low severity overall. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to the netlink interface that interacts with the L2TP subsystem, which typically is available to local users with appropriate privileges. An attacker can repeatedly issue create or modify commands to provoke notification failures, forcing the kernel to replay already successful operations and potentially leading to resource a local user or compromised application that can send netlink messages to the kernel.

Generated by OpenCVE AI on September 21, 2026 at 01:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the L2TP notification error suppression commit.
  • Configure L2TP‑using applications to treat notification‑error return codes as non‑critical and avoid retrying operations that have already succeeded.
  • If an immediate kernel upgrade is not possible, disable multicast notification emission for L2TP via the appropriate sysctl or adjust application retry limits to mitigate unnecessary resource consumption.

Generated by OpenCVE AI on September 21, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: l2tp: do not propagate multicast notification errors The tunnel create, tunnel modify, session create, and session modify netlink handlers send multicast notifications through helpers that can fail while allocating or encoding a message, or while multicasting it. For tunnel and session create/modify, a notification is sent after the live operation has completed. Returning a best-effort notification error as the command result can therefore report failure for an operation that already committed and can cause callers to retry and accumulate live objects. Keep sending notifications for listener visibility, but do not propagate their best-effort status as the command result. This also keeps the tunnel modify command consistent with the other notification-only paths.
Title net: l2tp: do not propagate multicast notification errors
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:42:51.542Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-80996

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:06.613

Modified: 2026-09-11T20:19:06.613

Link: CVE-2026-80996

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:51Z

Links: CVE-2026-80996 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:00:09Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling