PT-2026-106632 · Linux · Linux

CVE-2026-98303

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ipv4: icmp: reject RTN UNREACHABLE input routes in icmp route lookup
When the forward output route cannot be used in icmp route lookup(), it enters the "reverse path" and calls ip route input() on fl4 dec.daddr, the original packet's source address.
ip route input() only returns an error for truly invalid packets. For unreachable addresses it will succeed and return an input route whose dst.output is set to ip rt bug(). The existing check only rejects RTN LOCAL routes, so the RTN UNREACHABLE route types can still be returned and later used for output, syzkaller triggering a WARN ON ONCE() in ip rt bug() as bellow:
------------[ cut here ]------------ WARNING: net/ipv4/route.c:1273 at ip rt bug+0x14/0x20 RIP: 0010:ip rt bug+0x14/0x20 Call Trace: ip push pending frames+0xfa/0x100 icmp send+0x905/0xf10 ip options compile+0xc0/0xd0 ip rcv finish core+0x321/0xae0 ip rcv+0x1de/0x260 netif receive skb one core+0x11a/0x130 netif receive skb+0x7b/0x260 tun get user+0x11bf/0x1c10 ------------[ cut here ]------------
Reject input route that is RTN UNREACHABLE to fix it. The net warning is only printed for RTN LOCAL, as RTN UNREACHABLE is not the result of a race condition.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98303

Affected Products

Linux