Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98306— seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: seg6:在 IPIP 解封装时将 IPSKB_L3SLAVE 从 IP6SKB_L3SLAVE 设置 当 SRv6 数据包到达绑定到 VRF(虚拟路由和转发实例)的接口时,vrf_ip6_rcv() 会在 IP6CB(IPv6 控制块)中设置 IP6SKB_L3SLAVE,但 decap_and_validate() 从未在 IPCB(IPv4 控制块)中设置 IPSKB_L3SLAVE。在常见情况下,该标志位保持为 0(未设置);而在启用 CONFIG_IPV6_MIP

AI Predicted 4.7 Difficulty: Easy EPSS 0.18% · P7

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 891ef8dd2a8d14e4e73a81dcdb135b574c57f556< 1d9f5c78903dd25a3556229eb716dd465c5f3573 affected
891ef8dd2a8d14e4e73a81dcdb135b574c57f556< 72f410616000d21a0a6ec6c93a60301b9c92e95c affected
891ef8dd2a8d14e4e73a81dcdb135b574c57f556< e4d7c52f15f572608374947c6c802052e1a2fc82 affected
891ef8dd2a8d14e4e73a81dcdb135b574c57f556< 5130afa025c95faa621adf8bac525baeb2b290d2 affected
891ef8dd2a8d14e4e73a81dcdb135b574c57f556< f8fb4738ccef5f9d107845b05734a56352747b1a affected
891ef8dd2a8d14e4e73a81dcdb135b574c57f556< ddf60220c925b54a1714c4722fdbdb12833232d0 affected
891ef8dd2a8d14e4e73a81dcdb135b574c57f556< 8c16e1ccc082a3763dfc6bc2d3f658c1a6336f9d affected
891ef8dd2a8d14e4e73a81dcdb135b574c57f556< 7616242a2b37883f7322aaa1d2bd6cd0fed28315 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98306

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation When an SRv6 packet arrives on an interface enslaved to a VRF, vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate() has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of a reassembled outer packet could even set it, with no VRF involved. Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP decapsulation") then made the unreliable bit reliably clear. The effect of the missing flag is visible with End.DX4 when a delivery to a local address of the node reaches the socket lookup. For example, a UDP socket bound to the enslaved ingress interface does not receive any of the decapsulated packets, while an unbound socket outside the VRF does. This contradicts Documentation/networking/vrf.rst: by default the scope of an unbound UDP or TCP socket is limited to the default VRF. Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does the same for IPv6. The socket lookup then matches the decapsulated packet like any other packet received on that enslaved interface. Such a packet matches an unbound UDP or TCP socket only when udp_l3mdev_accept or tcp_l3mdev_accept is set.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 ~ 1d9f5c78903dd25a3556229eb716dd465c5f3573 -
Linux Linux 4.14 -

II. Public POCs for CVE-2026-98306

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98306

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98306 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98305 7.8 HIGH net: dsa: mxl862xx: disable the stats poll on teardown
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98306

No comments yet


Leave a comment