SB20260912377 - Improper Check or Handling of Exceptional Conditions in Linux kernel l2tp
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-80996)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause live L2TP objects to accumulate.
The vulnerability exists due to improper error handling in the L2TP netlink tunnel and session create and modify handlers when multicast notification delivery fails after a live operation completes. A local user can issue L2TP netlink create or modify commands that are erroneously reported as failed to cause live L2TP objects to accumulate.
Remediation
Install update from vendor's website.