CVE-2026-98278: net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check
In the Linux kernel, the following vulnerability has been resolved:
net: remove WARNONONCE() from the devfillforwardpath() loop check
ipipfillforwardpath() and ip6tnlfillforwardpath() look up the route to the tunnel's remote endpoint and set ctx->dev to its device, which is the tunnel itself when that route resolves back to the tunnel. devfillforwardpath() then makes no progress and trips WARNONONCE(lastdev == ctx->dev) as soon as a flowtable tries to offload a flow through the tunnel. That routing loop is a configuration any CAPNETADMIN user can set up, and iptunnelxmit() and ip6tnlxmit() already treat it as a tx error, so remove the warning and just fail the walk, as commit 008e7a7c293b ("net: remove WARNONONCE when accessing forward path array") did for the path stack overflow.