Impact
The Linux kernel L2TP netlink handlers send multicast notifications after tunnel or session creation or modification. When the notification helper fails—whether during allocation, encoding, or multicasting—the legacy code returned that Callers interpret a non‑critical failure as a genuine operation failure and can retry, creating duplicate tunnels or sessions and potentially exhausting kernel resources. This flaw is a classic resource‑allocation weakness (CWE‑770) that results in a low‑severity impact but can lead to a denial‑of‑service if the retry logic is not addressed.
Affected Systems
All Linux kernels that contain the stock L2TP implementation without the commit that suppresses propagation of notification errors are affected. The advisory does not list specific kernel versions, so users should inspect their running kernel version or its build configuration to determine whether the change is present. Distributions that ship the upstream kernel with the L2TP subsystem are included.
Risk and Exploitability
The CVSS score of 4.4 indicates a low severity overall. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to the netlink interface that interacts with the L2TP subsystem, which typically is available to local users with appropriate privileges. An attacker can repeatedly issue create or modify commands to provoke notification failures, forcing the kernel to replay already successful operations and potentially leading to resource a local user or compromised application that can send netlink messages to the kernel.
OpenCVE Enrichment
Debian DSA