CVE-2026-74657: ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
In the Linux kernel, the following vulnerability has been resolved:
ipv4: Fix fibnlmsgsize() for RTAVIA nexthops
fibnlmsgsize() still estimates nexthop space as if every gateway is encoded as an IPv4 RTAGATEWAY attribute. IPv4 routes can also carry an IPv6 gateway, which fibnexthopinfo() dumps as RTAVIA.
As a result, route notifications can allocate an skb that is too small. fibdumpinfo() then fails with -EMSGSIZE and rtmsgfib() hits the WARNON() that marks such failures as a fibnlmsgsize() bug. With paniconwarn set, this becomes a kernel panic.
Mirror the actual nexthop dump layout in fibnlmsgsize(): account for IPv6 nexthop gateways dumped as RTAVIA, for the no-header rtnexthop layout used inside RTAMULTIPATH, and for RTAFLOW only when it is actually present.