---
id: CVE-2026-98306
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation

  When an SRv6 packet arrives on an interface enslaved to a VRF,
  vrf_ip6_rcv() sets IP6SKB_L3SLAVE in I…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation

  When an SRv6 packet arrives on an interface enslaved to a VRF,
  vrf_ip6_rcv() sets IP6SKB_L3SLAVE in I…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    1d9f5c78903dd25a3556229eb716dd465c5f3573
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    72f410616000d21a0a6ec6c93a60301b9c92e95c
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    e4d7c52f15f572608374947c6c802052e1a2fc82
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    5130afa025c95faa621adf8bac525baeb2b290d2
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    f8fb4738ccef5f9d107845b05734a56352747b1a
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    ddf60220c925b54a1714c4722fdbdb12833232d0
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    8c16e1ccc082a3763dfc6bc2d3f658c1a6336f9d
  - >-
    Linux >= 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 <
    7616242a2b37883f7322aaa1d2bd6cd0fed28315
  - Linux 4.14
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:21.787'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98306'
references:
  - url: 'https://git.kernel.org/stable/c/1d9f5c78903dd25a3556229eb716dd465c5f3573'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5130afa025c95faa621adf8bac525baeb2b290d2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/72f410616000d21a0a6ec6c93a60301b9c92e95c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7616242a2b37883f7322aaa1d2bd6cd0fed28315'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8c16e1ccc082a3763dfc6bc2d3f658c1a6336f9d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ddf60220c925b54a1714c4722fdbdb12833232d0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e4d7c52f15f572608374947c6c802052e1a2fc82'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f8fb4738ccef5f9d107845b05734a56352747b1a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.411Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation

When an SRv6 packet arrives on an interface enslaved to a VRF,
vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate()
has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the
common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of
a reassembled outer packet could even set it, with no VRF involved.
Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP
decapsulation") then made the unreliable bit reliably clear.

The effect of the missing flag is visible with End.DX4 when a
delivery to a local address of the node reaches the socket lookup.
For example, a UDP socket bound to the enslaved ingress interface
does not receive any of the decapsulated packets, while an unbound
socket outside the VRF does.
This contradicts Documentation/networking/vrf.rst: by default the
scope of an unbound UDP or TCP socket is limited to the default VRF.

Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does
the same for IPv6. The socket lookup then matches the decapsulated
packet like any other packet received on that enslaved interface. Such
a packet matches an unbound UDP or TCP socket only when
udp_l3mdev_accept or tcp_l3mdev_accept is set.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
