{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup  When the forward output route cannot be used in icmp_route_lookup(), it enters the \"reverse path\" and calls ip_route_input() on fl4_dec.daddr, the original packet's source address.  ip_route_input() only returns an error for truly invalid packets. For unreachable addresses it will succeed and return an input route whose dst.output is set to ip_rt_bug(). The existing check only rejects RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned and later used for output, syzkaller triggering a WARN_ON_ONCE() in ip_rt_bug() as bellow:   ------------[ cut here ]------------  WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20  RIP: 0010:ip_rt_bug+0x14/0x20  Call Trace:   ip_push_pending_frames+0xfa/0x100   __icmp_send+0x905/0xf10   ip_options_compile+0xc0/0xd0   ip_rcv_finish_core+0x321/0xae0   ip_rcv+0x1de/0x260   __netif_receive_skb_one_core+0x11a/0x130   netif_receive_skb+0x7b/0x260   tun_get_user+0x11bf/0x1c10  ------------[ cut here ]------------  Reject input route that is RTN_UNREACHABLE to fix it. The net warning is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of a race condition.",
  "id": "DEBIAN-CVE-2026-98303",
  "modified": "2026-10-07T04:47:30.800035913Z",
  "published": "2026-10-06T09:18:21.370Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98303"
    }
  ],
  "upstream": [
    "CVE-2026-98303"
  ]
}