From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3268D38E5DA for ; Fri, 11 Sep 2026 19:48:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156141; cv=none; b=cfQznj0t6wrHHUikUyZkIrcyggDs4aWewqPglYkw+uhPJ/JbcHBpiYZBTEB1MxjIcudv7Oqbpb4uLeyphmmQ07nPqByIQdtk/soV4czWZFkUwn82iEjCbT1GBpvvAViIwrc8mpeyh7whnC3YLOxuBr6RoSWMZZwM89Gv9OAaLto= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156141; c=relaxed/simple; bh=viobzoDHuL9dhM4t22fsYZNPKzGEhcUgWzOUKAz4wyg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=hBVqd50VV7ARzAiMnAUVoGcnxEE2er0fEqG54sIvStbprDrTCIz+iKgaGDdtnjVB+P3D1rY6bO17UHU4OZdTOyVXPWam2iWzaCacxYiUUGR9mPWLcknabL+BvT10ML2MksfHcrkeMQc6/CRCYenkD7ukS3uB90wDslw4Z3InGzs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=hv0EsRJJ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="hv0EsRJJ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A77C21F0089D; Fri, 11 Sep 2026 19:48:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156124; bh=82sVwKzjor1rb6F5L15/6olxE3mWgGSxws+3JUJd6Xs=; h=From:To:Cc:Subject:Date:Reply-To; b=hv0EsRJJZIw0CpJ2fpwPtNlHZwBUIJVcrzKufADUKo91OC5r/ryWrRF9l8vZ11L8V izEaQx25e4HGlCpVJLPOivAqSbBJ4REuU4RR9ubOtL194U16Q1hIo7wVWj35HhPIaL zUegN2t8wfmj7uRzNiC+AzI1UcVnoSxlHQCtam38= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80996: net: l2tp: do not propagate multicast notification errors Date: Fri, 11 Sep 2026 21:41:42 +0200 Message-ID: <2026091150-CVE-2026-80996-8136@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2953; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=W4JYETKn+4YRJhacC8gLkuC2qWcYdG86sPQUoBKGo2A=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIp0eO7TMfmW5J2Oq1r+3F0xCHtXVFEfO8Pd8UuH0T zix5lZTRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEzE/QnDPH1tR7O7rV7shet2 vN9kN9c6Tm5DIMP8qvfLaxi1tC9N3HrRe8LtlSwPdnl9AQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net: l2tp: do not propagate multicast notification errors The tunnel create, tunnel modify, session create, and session modify netlink handlers send multicast notifications through helpers that can fail while allocating or encoding a message, or while multicasting it. For tunnel and session create/modify, a notification is sent after the live operation has completed. Returning a best-effort notification error as the command result can therefore report failure for an operation that already committed and can cause callers to retry and accumulate live objects. Keep sending notifications for listener visibility, but do not propagate their best-effort status as the command result. This also keeps the tunnel modify command consistent with the other notification-only paths. The Linux kernel CVE team has assigned CVE-2026-80996 to this issue. Affected and fixed versions =========================== Issue introduced in 4.0 with commit 33f72e6f0c67f673fd0c63a8182dbd9ffb8cf50b and fixed in 6.12.109 with commit 0fe037d5eaad938aa3e9143ee071aa237750b42b Issue introduced in 4.0 with commit 33f72e6f0c67f673fd0c63a8182dbd9ffb8cf50b and fixed in 6.18.50 with commit 9c340473f4822bb31b151c19afd17448eda5acd1 Issue introduced in 4.0 with commit 33f72e6f0c67f673fd0c63a8182dbd9ffb8cf50b and fixed in 7.2.4 with commit 50c4038f1670bf9a80c6a58ae83d1602decd8481 Issue introduced in 4.0 with commit 33f72e6f0c67f673fd0c63a8182dbd9ffb8cf50b and fixed in 7.3-rc1 with commit af20e269f7459d2ce69887fdf2fad7caf986c865 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80996 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/l2tp/l2tp_netlink.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/0fe037d5eaad938aa3e9143ee071aa237750b42b https://git.kernel.org/stable/c/9c340473f4822bb31b151c19afd17448eda5acd1 https://git.kernel.org/stable/c/50c4038f1670bf9a80c6a58ae83d1602decd8481 https://git.kernel.org/stable/c/af20e269f7459d2ce69887fdf2fad7caf986c865