CVE-2026-98303: ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
In the Linux kernel, the following vulnerability has been resolved:
ipv4: icmp: reject RTNUNREACHABLE input routes in icmproutelookup
When the forward output route cannot be used in icmproutelookup(), it enters the "reverse path" and calls iprouteinput() on fl4dec.daddr, the original packet's source address.
iprouteinput() only returns an error for truly invalid packets. For unreachable addresses it will succeed and return an input route whose dst.output is set to iprtbug(). The existing check only rejects RTNLOCAL routes, so the RTNUNREACHABLE route types can still be returned and later used for output, syzkaller triggering a WARNONONCE() in iprtbug() as bellow:
------------[ cut here ]------------ WARNING: net/ipv4/route.c:1273 at iprtbug+0x14/0x20 RIP: 0010:iprtbug+0x14/0x20 Call Trace: ippushpendingframes+0xfa/0x100 icmpsend+0x905/0xf10 ipoptionscompile+0xc0/0xd0 iprcvfinishcore+0x321/0xae0 iprcv+0x1de/0x260 netifreceiveskbonecore+0x11a/0x130 netifreceiveskb+0x7b/0x260 tungetuser+0x11bf/0x1c10 ------------[ cut here ]------------
Reject input route that is RTNUNREACHABLE to fix it. The net warning is only printed for RTNLOCAL, as RTNUNREACHABLE is not the result of a race condition.