{"id":"CVE-2026-80996","summary":"net: l2tp: do not propagate multicast notification errors","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: l2tp: do not propagate multicast notification errors\n\nThe tunnel create, tunnel modify, session create, and session modify\nnetlink handlers send multicast notifications through helpers that can fail\nwhile allocating or encoding a message, or while multicasting it.\n\nFor tunnel and session create/modify, a notification is sent after the live\noperation has completed. Returning a best-effort notification error as the\ncommand result can therefore report failure for an operation that already\ncommitted and can cause callers to retry and accumulate live objects.\n\nKeep sending notifications for listener visibility, but do not propagate\ntheir best-effort status as the command result. This also keeps the tunnel\nmodify command consistent with the other notification-only paths.","modified":"2026-09-13T03:47:09.263082327Z","published":"2026-09-11T19:42:51.542Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80996.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0fe037d5eaad938aa3e9143ee071aa237750b42b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/50c4038f1670bf9a80c6a58ae83d1602decd8481"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9c340473f4822bb31b151c19afd17448eda5acd1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af20e269f7459d2ce69887fdf2fad7caf986c865"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80996.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80996"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"33f72e6f0c67f673fd0c63a8182dbd9ffb8cf50b"},{"fixed":"0fe037d5eaad938aa3e9143ee071aa237750b42b"},{"fixed":"9c340473f4822bb31b151c19afd17448eda5acd1"},{"fixed":"50c4038f1670bf9a80c6a58ae83d1602decd8481"},{"fixed":"af20e269f7459d2ce69887fdf2fad7caf986c865"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80996.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80996.json"}}],"schema_version":"1.9.0"}