{"id":"CVE-2026-80996","title":"kernel: net: l2tp: do not propagate multicast notification errors (CVE-2026-80996)","summary":"A flaw was found in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) networking component. Specifically, the netlink handlers responsible for creating and modifying L2TP tunnels and sessions may fail to propagate multicast notification…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-770","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:16:32+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80996.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80996.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80996"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532170"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80996"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80996"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80996.mbox"},{"url":"https://git.kernel.org/stable/c/0fe037d5eaad938aa3e9143ee071aa237750b42b"},{"url":"https://git.kernel.org/stable/c/9c340473f4822bb31b151c19afd17448eda5acd1"},{"url":"https://git.kernel.org/stable/c/50c4038f1670bf9a80c6a58ae83d1602decd8481"},{"url":"https://git.kernel.org/stable/c/af20e269f7459d2ce69887fdf2fad7caf986c865"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00168,"epssPercentile":0.06448,"ingestedAt":"2026-09-14T00:35:28.531Z","slug":"CVE-2026-80996","body":"## Overview\n\nA flaw was found in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) networking component. Specifically, the netlink handlers responsible for creating and modifying L2TP tunnels and sessions may fail to propagate multicast notification errors. This can lead to calling applications retrying operations that have already successfully completed, potentially causing an accumulation of live objects. Such an accumulation could result in resource exhaustion, leading to a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80996.json)\n\n**kernel: net: l2tp: do not propagate multicast notification errors** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204149,"id":"CVE-2026-80996","ts":1789490232982,"field":"cvss","old":null,"new":"5.5"},{"seq":204148,"id":"CVE-2026-80996","ts":1789490232982,"field":"severity","old":"none","new":"medium"},{"seq":147656,"id":"CVE-2026-80996","ts":1789270211764,"field":"cvss","old":null,"new":"4.4"},{"seq":147655,"id":"CVE-2026-80996","ts":1789270211764,"field":"severity","old":"none","new":"medium"},{"seq":109408,"id":"CVE-2026-80996","ts":1789183731798,"field":"cvss","old":null,"new":"4.4"},{"seq":109407,"id":"CVE-2026-80996","ts":1789183731798,"field":"severity","old":"none","new":"medium"}]}