CVE-2026-98303

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup When the forward output route cannot be used in icmp_route_lookup(), it enters the "reverse path" and calls ip_route_input() on fl4_dec.daddr, the original packet's source address. ip_route_input() only returns an error for truly invalid packets. For unreachable addresses it will succeed and return an input route whose dst.output is set to ip_rt_bug(). The existing check only rejects RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned and later used for output, syzkaller triggering a WARN_ON_ONCE() in ip_rt_bug() as bellow: ------------[ cut here ]------------ WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20 RIP: 0010:ip_rt_bug+0x14/0x20 Call Trace: ip_push_pending_frames+0xfa/0x100 __icmp_send+0x905/0xf10 ip_options_compile+0xc0/0xd0 ip_rcv_finish_core+0x321/0xae0 ip_rcv+0x1de/0x260 __netif_receive_skb_one_core+0x11a/0x130 netif_receive_skb+0x7b/0x260 tun_get_user+0x11bf/0x1c10 ------------[ cut here ]------------ Reject input route that is RTN_UNREACHABLE to fix it. The net warning is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of a race condition.

Package Linux Kernel
Published 2026-10-06
Last modified 2026-10-06
Patch available
Yes

Affected versions

Linux kernel versions 2.6.25 and later are affected. Fixed in 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, 7.3-rc4 and their respective stable series.

Affected from
≥ 2.6.25
Fixed in
✓ 6.1.189 6.1.x ✓ 6.6.158 6.6.x ✓ 6.12.112 6.12.x ✓ 6.18.54 6.18.x ✓ 7.2.8 7.2.x ✓ 7.3-rc4

Frequently asked questions

  • What is CVE-2026-98303?

    CVE-2026-98303 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.25 onward and has been patched in 6.1.189, 6.6.158, 6.12.112 and others. CVE-2026-98303 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98303?

    Yes. CVE-2026-98303 has been patched. Fixed versions include 6.1.189, 6.6.158, 6.12.112 and others. If you are running Linux kernel 2.6.25 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98303 actively exploited?

    No. CVE-2026-98303 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.