PT-2026-106632 · Linux · Linux

CVE-2026-98303

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ipv4: icmp: reject RTN UNREACHABLE input routes in icmp route lookup
When the forward output route cannot be used in icmp route lookup(), it enters the "reverse path" and calls ip route input() on fl4 dec.daddr, the original packet's source address.
ip route input() only returns an error for truly invalid packets. For unreachable addresses it will succeed and return an input route whose dst.output is set to ip rt bug(). The existing check only rejects RTN LOCAL routes, so the RTN UNREACHABLE route types can still be returned and later used for output, syzkaller triggering a WARN ON ONCE() in ip rt bug() as bellow:
------------[ cut here ]------------ WARNING: net/ipv4/route.c:1273 at ip rt bug+0x14/0x20 RIP: 0010:ip rt bug+0x14/0x20 Call Trace: ip push pending frames+0xfa/0x100 icmp send+0x905/0xf10 ip options compile+0xc0/0xd0 ip rcv finish core+0x321/0xae0 ip rcv+0x1de/0x260 netif receive skb one core+0x11a/0x130 netif receive skb+0x7b/0x260 tun get user+0x11bf/0x1c10 ------------[ cut here ]------------
Reject input route that is RTN UNREACHABLE to fix it. The net warning is only printed for RTN LOCAL, as RTN UNREACHABLE is not the result of a race condition.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98303

Produtos afetados

Linux