seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
Summary
| CVE | CVE-2026-98306 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:18:21 UTC |
| Updated | 2026-10-06 09:18:21 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation When an SRv6 packet arrives on an interface enslaved to a VRF, vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate() has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of a reassembled outer packet could even set it, with no VRF involved. Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP decapsulation") then made the unreliable bit reliably clear. The effect of the missing flag is visible with End.DX4 when a delivery to a local address of the node reaches the socket lookup. For example, a UDP socket bound to the enslaved ingress interface does not receive any of the decapsulated packets, while an unbound socket outside the VRF does. This contradicts Documentation/networking/vrf.rst: by default the scope of an unbound UDP or TCP socket is limited to the default VRF. Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does the same for IPv6. The socket lookup then matches the decapsulated packet like any other packet received on that enslaved interface. Such a packet matches an unbound UDP or TCP socket only when udp_l3mdev_accept or tcp_l3mdev_accept is set. |
Risk And Classification
EPSS: 0.001840000 probability, percentile 0.072970000 (date 2026-10-06)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 1d9f5c78903dd25a3556229eb716dd465c5f3573 git | Not specified |
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 72f410616000d21a0a6ec6c93a60301b9c92e95c git | Not specified |
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 e4d7c52f15f572608374947c6c802052e1a2fc82 git | Not specified |
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 5130afa025c95faa621adf8bac525baeb2b290d2 git | Not specified |
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 f8fb4738ccef5f9d107845b05734a56352747b1a git | Not specified |
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 ddf60220c925b54a1714c4722fdbdb12833232d0 git | Not specified |
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 8c16e1ccc082a3763dfc6bc2d3f658c1a6336f9d git | Not specified |
| CNA | Linux | Linux | affected 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 7616242a2b37883f7322aaa1d2bd6cd0fed28315 git | Not specified |
| CNA | Linux | Linux | affected 4.14 | Not specified |
| CNA | Linux | Linux | unaffected 4.14 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.271 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.222 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.189 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.158 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.112 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.54 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.8 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc4 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/8c16e1ccc082a3763dfc6bc2d3f658c1a6336f9d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ddf60220c925b54a1714c4722fdbdb12833232d0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f8fb4738ccef5f9d107845b05734a56352747b1a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1d9f5c78903dd25a3556229eb716dd465c5f3573 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7616242a2b37883f7322aaa1d2bd6cd0fed28315 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5130afa025c95faa621adf8bac525baeb2b290d2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e4d7c52f15f572608374947c6c802052e1a2fc82 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/72f410616000d21a0a6ec6c93a60301b9c92e95c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.