CVE-2026-98303

Source
https://cve.org/CVERecord?id=CVE-2026-98303
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98303.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98303
Downstream
Published
2026-10-06T08:46:00Z
Modified
2026-10-08T02:50:03Z
Summary
ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup

When the forward output route cannot be used in icmp_route_lookup(), it enters the "reverse path" and calls ip_route_input() on fl4_dec.daddr, the original packet's source address.

ip_route_input() only returns an error for truly invalid packets. For unreachable addresses it will succeed and return an input route whose dst.output is set to ip_rt_bug(). The existing check only rejects RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned and later used for output, syzkaller triggering a WARN_ON_ONCE() in ip_rt_bug() as bellow:

------------[ cut here ]------------ WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20 RIP: 0010:ip_rt_bug+0x14/0x20 Call Trace: ip_push_pending_frames+0xfa/0x100 __icmp_send+0x905/0xf10 ip_options_compile+0xc0/0xd0 ip_rcv_finish_core+0x321/0xae0 ip_rcv+0x1de/0x260 __netif_receive_skb_one_core+0x11a/0x130 netif_receive_skb+0x7b/0x260 tun_get_user+0x11bf/0x1c10 ------------[ cut here ]------------

Reject input route that is RTN_UNREACHABLE to fix it. The net warning is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of a race condition.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98303.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b7817f3a959ed99d7443afc12f78a7e1fcc2063
Fixed
06083cea4a3b95f5ebc85312f97d7086e6c9e782
Fixed
83aa83f81a8fec30ff5372dee60b2f0561bcb2ca
Fixed
cac69c50716c712ef0114837c9427da66066124c
Fixed
1af2d87964d87ba7626d96928d68c09158b5a223
Fixed
fda3000147dc96c75ba162f680bec0a9fecf3037
Fixed
2998147b59c9df0a51477c7a6b3d1f0ba3127dd4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98303.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.25
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98303.json"