CVE-2026-98317: neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
In the Linux kernel, the following vulnerability has been resolved:
neighbour: Enforce min/max to NDTPAINTERVALPROBETIMEMS.
NDTPAINTERVALPROBETIMEMS sets .type and .min but misses .validationtype, so no validation is applied:
# ynl --family rt-neigh --do setneightbl \ --json '{"name": "arpcache", "parms": {"interval-probe-time-ms": 0}}'
# ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arpcache" and has("config")) | .parms["interval-probe-time-ms"]' 0
Moreover, nlagetmsecs() uses msecstojiffies(), and u64 is silently cast to u32, so a larger value can bypass the min check:
e.g. 4294967296 == 0x100000000
# ynl --family rt-neigh --do setneightbl \ --json '{"name": "arpcache", "parms": {"interval-probe-time-ms": 4294967296}}'
# ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arpcache" and has("config")) | .parms["interval-probe-time-ms"]' 0
msecstojiffies() returns MAXJIFFYOFFSET if the value is larger than INTMAX. Also, INTMAX ms overflows int NEIGHVAR() when HZ > 1000 (Alpha, MIPS), and passing a negative integer to queuedelayedwork(unsigned long delay) causes sign extension, which wraps around the expiry time to the past, resulting in it being handled as 0 delay in the timer wheel.
Let's use NLAPOLICYFULLRANGE() and limit the max to 1 day.
The same max check is applied to sysctl as well.
Note that this controls the probe interval for NTFMANAGED entries, so the max of 1 day is unlikely to break any deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enforce a maximum interval-probe-time-ms value of 1 day for NDTPA_INTERVAL_PROBE_TIME_MS and apply the same maximum check to the corresponding sysctl.
Linux kernel neighbor table interval-probe-time-ms = maximum 1 day