SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-80733

UNKNOWN · CVSS N/A EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-19

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of multicast loopback for non-INET sockets, specifically when the sk_mc_loop() function is invoked for sockets like AF_PACKET. This can lead to unnecessary warnings in the system logs, potentially obscuring other critical issues. Organizations using Linux systems, particularly those utilizing raw or packet sockets over virtual devices, should prioritize addressing this to ensure optimal performance and log clarity.

CVE
CVE-2026-80733
Severity
UNKNOWN
CVSS
N/A
EPSS
0.21%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net: remove WARN_ON_ONCE() from sk_mc_loop() sk_mc_loop() can be called for sockets that are neither AF_INET nor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet socket over virtual devices such as VRF or ipvlan). In such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls through the switch statement and triggers WARN_ON_ONCE(1). Non-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP options, so loopback should default to true without generating a warning.