-

CVE-2026-98303

ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup

In the Linux kernel, the following vulnerability has been resolved:

ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup

When the forward output route cannot be used in icmp_route_lookup(),
it enters the "reverse path" and calls ip_route_input() on fl4_dec.daddr,
the original packet's source address.

ip_route_input() only returns an error for truly invalid packets. For
unreachable addresses it will succeed and return an input route whose
dst.output is set to ip_rt_bug(). The existing check only rejects
RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned
and later used for output, syzkaller triggering a WARN_ON_ONCE()
in ip_rt_bug() as bellow:

 ------------[ cut here ]------------
 WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20
 RIP: 0010:ip_rt_bug+0x14/0x20
 Call Trace:
  ip_push_pending_frames+0xfa/0x100
  __icmp_send+0x905/0xf10
  ip_options_compile+0xc0/0xd0
  ip_rcv_finish_core+0x321/0xae0
  ip_rcv+0x1de/0x260
  __netif_receive_skb_one_core+0x11a/0x130
  netif_receive_skb+0x7b/0x260
  tun_get_user+0x11bf/0x1c10
 ------------[ cut here ]------------

Reject input route that is RTN_UNREACHABLE to fix it. The net warning
is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of
a race condition.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8b7817f3a959ed99d7443afc12f78a7e1fcc2063
Version < 06083cea4a3b95f5ebc85312f97d7086e6c9e782
Status affected
Version 8b7817f3a959ed99d7443afc12f78a7e1fcc2063
Version < 83aa83f81a8fec30ff5372dee60b2f0561bcb2ca
Status affected
Version 8b7817f3a959ed99d7443afc12f78a7e1fcc2063
Version < cac69c50716c712ef0114837c9427da66066124c
Status affected
Version 8b7817f3a959ed99d7443afc12f78a7e1fcc2063
Version < 1af2d87964d87ba7626d96928d68c09158b5a223
Status affected
Version 8b7817f3a959ed99d7443afc12f78a7e1fcc2063
Version < fda3000147dc96c75ba162f680bec0a9fecf3037
Status affected
Version 8b7817f3a959ed99d7443afc12f78a7e1fcc2063
Version < 2998147b59c9df0a51477c7a6b3d1f0ba3127dd4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.25
Status affected
Version 0
Version < 2.6.25
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/06083cea4a3b95f5ebc85312f97d7086e6c9e782
https://git.kernel.org/stable/c/83aa83f81a8fec30ff5372dee60b2f0561bcb2ca
https://git.kernel.org/stable/c/cac69c50716c712ef0114837c9427da66066124c
https://git.kernel.org/stable/c/1af2d87964d87ba7626d96928d68c09158b5a223
https://git.kernel.org/stable/c/fda3000147dc96c75ba162f680bec0a9fecf3037
https://git.kernel.org/stable/c/2998147b59c9df0a51477c7a6b3d1f0ba3127dd4