CVE-2026-98317: neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

neighbour: Enforce min/max to NDTPAINTERVALPROBETIMEMS.

NDTPAINTERVALPROBETIMEMS sets .type and .min but misses .validationtype, so no validation is applied:

# ynl --family rt-neigh --do setneightbl \ --json '{"name": "arpcache", "parms": {"interval-probe-time-ms": 0}}'

# ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arpcache" and has("config")) | .parms["interval-probe-time-ms"]' 0

Moreover, nlagetmsecs() uses msecstojiffies(), and u64 is silently cast to u32, so a larger value can bypass the min check:

e.g. 4294967296 == 0x100000000

# ynl --family rt-neigh --do setneightbl \ --json '{"name": "arpcache", "parms": {"interval-probe-time-ms": 4294967296}}'

# ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arpcache" and has("config")) | .parms["interval-probe-time-ms"]' 0

msecstojiffies() returns MAXJIFFYOFFSET if the value is larger than INTMAX. Also, INTMAX ms overflows int NEIGHVAR() when HZ > 1000 (Alpha, MIPS), and passing a negative integer to queuedelayedwork(unsigned long delay) causes sign extension, which wraps around the expiry time to the past, resulting in it being handled as 0 delay in the timer wheel.

Let's use NLAPOLICYFULLRANGE() and limit the max to 1 day.

The same max check is applied to sysctl as well.

Note that this controls the probe interval for NTFMANAGED entries, so the max of 1 day is unlikely to break any deployments.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Enforce a maximum interval-probe-time-ms value of 1 day for NDTPA_INTERVAL_PROBE_TIME_MS and apply the same maximum check to the corresponding sysctl.

    Linux kernel neighbor table interval-probe-time-ms = maximum 1 day

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203