CVE-2026-80996

Source
https://cve.org/CVERecord?id=CVE-2026-80996
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80996.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80996
Downstream
Published
2026-09-11T19:42:51Z
Modified
2026-09-13T03:47:09Z
Summary
net: l2tp: do not propagate multicast notification errors
Details

In the Linux kernel, the following vulnerability has been resolved:

net: l2tp: do not propagate multicast notification errors

The tunnel create, tunnel modify, session create, and session modify netlink handlers send multicast notifications through helpers that can fail while allocating or encoding a message, or while multicasting it.

For tunnel and session create/modify, a notification is sent after the live operation has completed. Returning a best-effort notification error as the command result can therefore report failure for an operation that already committed and can cause callers to retry and accumulate live objects.

Keep sending notifications for listener visibility, but do not propagate their best-effort status as the command result. This also keeps the tunnel modify command consistent with the other notification-only paths.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80996.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
33f72e6f0c67f673fd0c63a8182dbd9ffb8cf50b
Fixed
0fe037d5eaad938aa3e9143ee071aa237750b42b
Fixed
9c340473f4822bb31b151c19afd17448eda5acd1
Fixed
50c4038f1670bf9a80c6a58ae83d1602decd8481
Fixed
af20e269f7459d2ce69887fdf2fad7caf986c865

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80996.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80996.json"