CVE-2026-80733: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: remove WARN_ON_ONCE() from sk_mc_loop() sk_mc_loop() can be called for sockets that are neither AF_INET nor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet socket over virtual devices such as VRF or ipvlan). In such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls through the switch statement and triggers WARN_ON_ONCE(1). Non-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP options, so loopback should default to true without generating a warning.
Affected products
- Linux Linux: from 3.14.40, before 3.15 (fixed in 3.15); from 3.18.13, before 3.19 (fixed in 3.19); from 3.19.6, before 3.20 (fixed in 3.20); from 4.0, before 5.10.265 (fixed in 5.10.265); from 5.11, before 5.15.216 (fixed in 5.15.216); from 5.16, before 6.1.183 (fixed in 6.1.183); …
Published 2026-09-03. Last modified 2026-09-03.