Answer in brief
CVE-2026-98306 records a Unknown severity vulnerability in seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <1d9f5c78903dd25a3556229eb716dd465c5f3573 || >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <72f410616000d21a0a6ec6c93a60301b9c92e95c || >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <e4d7c52f15f572608374947c6c802052e1a2fc82 || >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <5130afa025c95faa621adf8bac525baeb2b290d2 || >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <f8fb4738ccef5f9d107845b05734a56352747b1a || >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <ddf60220c925b54a1714c4722fdbdb12833232d0 || >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <8c16e1ccc082a3763dfc6bc2d3f658c1a6336f9d || >=891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <7616242a2b37883f7322aaa1d2bd6cd0fed28315 | 1d9f5c78903dd25a3556229eb716dd465c5f3573, 72f410616000d21a0a6ec6c93a60301b9c92e95c, e4d7c52f15f572608374947c6c802052e1a2fc82, 5130afa025c95faa621adf8bac525baeb2b290d2, f8fb4738ccef5f9d107845b05734a56352747b1a, ddf60220c925b54a1714c4722fdbdb12833232d0, 8c16e1ccc082a3763dfc6bc2d3f658c1a6336f9d, 7616242a2b37883f7322aaa1d2bd6cd0fed28315 |
| Linux/Linuxgeneric | 4.14 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation When an SRv6 packet arrives on an interface enslaved to a VRF, vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate() has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of a reassembled outer packet could even set it, with no VRF involved. Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP decapsulation") then made the unreliable bit reliably clear. The effect of the missing flag is visible with End.DX4 when a delivery to a local address of the node reaches the socket lookup. For example, a UDP socket bound to the enslaved ingress interface does not receive any of the decapsulated packets, while an unbound socket outside the VRF does. This contradicts Documentation/networking/vrf.rst: by default the scope of an unbound UDP or TCP socket is limited to the default VRF. Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does the same for IPv6. The socket lookup then matches the decapsulated packet like any other packet received on that enslaved interface. Such a packet matches an unbound UDP or TCP socket only when udp_l3mdev_accept or tcp_l3mdev_accept is set.
Quoted source text, attributed separately from HOL analysis.