« Volver al listado

CVE-2026-98278

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check

ipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the route to the tunnel's remote endpoint and set ctx->dev to its device, which is the tunnel itself when that route resolves back to the tunnel. dev_fill_forward_path() then makes no progress and trips WARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to offload a flow through the tunnel.

Leer descripción completaMostrar menos

That routing loop is a configuration any CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and ip6_tnl_xmit() already treat it as a tx error, so remove the warning and just fail the walk, as commit 008e7a7c293b ("net: remove WARN_ON_ONCE when accessing forward path array") did for the path stack overflow.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98278",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ab427db17885814069bae891834f20842f0ac3a4",
              "lessThan": "d8eb177632dacda28bc6130c2105afbf5b791eb0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab427db17885814069bae891834f20842f0ac3a4",
              "lessThan": "150dba2c69e93302af24a0c868eebe4871e2e107",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/core/dev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/core/dev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:17.660",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/150dba2c69e93302af24a0c868eebe4871e2e107",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d8eb177632dacda28bc6130c2105afbf5b791eb0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check\n\nipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the\nroute to the tunnel's remote endpoint and set ctx->dev to its device,\nwhich is the tunnel itself when that route resolves back to the tunnel.\ndev_fill_forward_path() then makes no progress and trips\nWARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to\noffload a flow through the tunnel. That routing loop is a configuration\nany CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and\nip6_tnl_xmit() already treat it as a tx error, so remove the warning and\njust fail the walk, as commit 008e7a7c293b (\"net: remove WARN_ON_ONCE\nwhen accessing forward path array\") did for the path stack overflow."
    }
  ],
  "lastModified": "2026-10-06T09:18:17.660",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}