Re: [PATCH net v2 0/1] net: l2tp: do not propagate multicast notification errors
From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-08-24 18:51:12
Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski [off-list ref]: On Thu, 20 Aug 2026 18:40:27 +0000 you wrote:
Hi Linux kernel maintainers, We found and validated a issue in net/l2tp/l2tp_netlink.c. The bug is reachable by a non-root user via user and net namespace. The failure is observed on the unpatched kernel, not theoretical: the original PoC returned ENOBUFS after publishing live objects and then accumulated sessions. Here, that reachability statement refers to the finite state-commit trigger; the OOM transcript below is a separate root initramfs leak-mode run (UID 0, PID 1) used to make the leak and panic deterministic. We've tested it, and it should not affect any other functionality. Regression coverage includes the root namespace and an unprivileged user/net namespace, with notification-queue pressure and successful ACK paths for all three state-changing PoC commands; tunnel_modify was reviewed as a notification-only command path but was not a separate PoC trigger. No broader regression suite was run. The finite fixed-kernel runs returned ACK success for all three state-changing PoC commands in both namespaces. The leak run returned ENOBUFS and reached OOM after 41984 hidden Ethernet sessions. [...]
Here is the summary with links:
- [net,v2,1/1] net: l2tp: do not propagate multicast notification errors
https://git.kernel.org/netdev/net/c/af20e269f745
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html