PT-2026-106632 · Linux · Linux
CVE-2026-98303
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipv4: icmp: reject RTN UNREACHABLE input routes in icmp route lookup
When the forward output route cannot be used in icmp route lookup(),
it enters the "reverse path" and calls ip route input() on fl4 dec.daddr,
the original packet's source address.
ip route input() only returns an error for truly invalid packets. For
unreachable addresses it will succeed and return an input route whose
dst.output is set to ip rt bug(). The existing check only rejects
RTN LOCAL routes, so the RTN UNREACHABLE route types can still be returned
and later used for output, syzkaller triggering a WARN ON ONCE()
in ip rt bug() as bellow:
------------[ cut here ]------------
WARNING: net/ipv4/route.c:1273 at ip rt bug+0x14/0x20
RIP: 0010:ip rt bug+0x14/0x20
Call Trace:
ip push pending frames+0xfa/0x100
icmp send+0x905/0xf10
ip options compile+0xc0/0xd0
ip rcv finish core+0x321/0xae0
ip rcv+0x1de/0x260
netif receive skb one core+0x11a/0x130
netif receive skb+0x7b/0x260
tun get user+0x11bf/0x1c10
------------[ cut here ]------------
Reject input route that is RTN UNREACHABLE to fix it. The net warning
is only printed for RTN LOCAL, as RTN UNREACHABLE is not the result of
a race condition.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux