PT-2026-106632 · Linux · Linux
CVE-2026-98303
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ipv4: icmp: reject RTN UNREACHABLE input routes in icmp route lookup
When the forward output route cannot be used in icmp route lookup(),
it enters the "reverse path" and calls ip route input() on fl4 dec.daddr,
the original packet's source address.
ip route input() only returns an error for truly invalid packets. For
unreachable addresses it will succeed and return an input route whose
dst.output is set to ip rt bug(). The existing check only rejects
RTN LOCAL routes, so the RTN UNREACHABLE route types can still be returned
and later used for output, syzkaller triggering a WARN ON ONCE()
in ip rt bug() as bellow:
------------[ cut here ]------------
WARNING: net/ipv4/route.c:1273 at ip rt bug+0x14/0x20
RIP: 0010:ip rt bug+0x14/0x20
Call Trace:
ip push pending frames+0xfa/0x100
icmp send+0x905/0xf10
ip options compile+0xc0/0xd0
ip rcv finish core+0x321/0xae0
ip rcv+0x1de/0x260
netif receive skb one core+0x11a/0x130
netif receive skb+0x7b/0x260
tun get user+0x11bf/0x1c10
------------[ cut here ]------------
Reject input route that is RTN UNREACHABLE to fix it. The net warning
is only printed for RTN LOCAL, as RTN UNREACHABLE is not the result of
a race condition.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux