Bug 2546540 (CVE-2026-98278) - CVE-2026-98278 kernel: net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check
Summary: CVE-2026-98278 kernel: net: remove WARN_ON_ONCE() from the dev_fill_forward_p...
Keywords:
Status: NEW
Alias: CVE-2026-98278
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 09:41 UTC by OSIDB Bzimport
Modified: 2026-10-09 09:02 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 09:41:03 UTC
In the Linux kernel, the following vulnerability has been resolved:

net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check

ipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the
route to the tunnel's remote endpoint and set ctx->dev to its device,
which is the tunnel itself when that route resolves back to the tunnel.
dev_fill_forward_path() then makes no progress and trips
WARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to
offload a flow through the tunnel. That routing loop is a configuration
any CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and
ip6_tnl_xmit() already treat it as a tx error, so remove the warning and
just fail the walk, as commit 008e7a7c293b ("net: remove WARN_ON_ONCE
when accessing forward path array") did for the path stack overflow.


Note You need to log in before you can comment on or make changes to this bug.