PT-2026-106607 · Linux · Linux

CVE-2026-98278

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: remove WARN ON ONCE() from the dev fill forward path() loop check
ipip fill forward path() and ip6 tnl fill forward path() look up the route to the tunnel's remote endpoint and set ctx->dev to its device, which is the tunnel itself when that route resolves back to the tunnel. dev fill forward path() then makes no progress and trips WARN ON ONCE(last dev == ctx->dev) as soon as a flowtable tries to offload a flow through the tunnel. That routing loop is a configuration any CAP NET ADMIN user can set up, and ip tunnel xmit() and ip6 tnl xmit() already treat it as a tx error, so remove the warning and just fail the walk, as commit 008e7a7c293b ("net: remove WARN ON ONCE when accessing forward path array") did for the path stack overflow.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98278

Affected Products

Linux